Impact
An integer underflow flaw, also known as wrap or wraparound, exists in Microsoft Defender. The underflow bypasses bounds checks and permits an attacker with local access to execute arbitrary code on the system. This vulnerability is classified as CWE‑191 and can lead to full system compromise, affecting confidentiality, integrity and availability.
Affected Systems
The affected product is the Microsoft Malware Protection Engine, the core component of Microsoft Defender. No version constraints are provided in the public data, implying that any installed instance may be vulnerable until a vendor update is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local code execution risk. The EPSS value of less than 1% suggests that, as of now, exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalogue. Based on the text, the attack vector is local: an unauthorized user must already have some level of access to trigger the integer underflow and run malicious code. No remote exploitation has been documented.
OpenCVE Enrichment