Impact
Integer overflow or wraparound in the Windows Defender Malware Protection Engine allows an attacker with local system access to run arbitrary code. The flaw originates from improper handling of unsigned integer values and buffer boundaries, corresponding to the weaknesses identified by CWE-122 and CWE-190. Successful exploitation would enable the attacker to execute code in the Defender process, potentially leading to broader system compromise.
Affected Systems
The vulnerability targets the Microsoft Malware Protection Engine component of Microsoft Defender. All installations that include this engine could be impacted; however, the CVE data does not specify affected product versions, so it is unclear which specific releases are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 signals a high‑severity local code‑execution flaw, while the EPSS score indicates a low probability of exploitation in the wild. Based on the description, the likely attack vector is local, requiring an attacker to supply crafted input to the Defender engine; no remote exploitation has been reported.
OpenCVE Enrichment