Description
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A time‑of‑check to time‑of‑use (TOCTOU) race condition exists in Microsoft Defender for Endpoint for Mac, allowing an attacker who already has local authorization to elevate privileges. The flaw arises when a check of a file or resource is performed before the resource is used, and the race can be exploited to trick the program into performing operations with higher privileges. The impact is the gain of elevated system rights, potentially compromising the entire Mac system used by the attacker. The weakness is a classic race‑condition flaw (CWE‑367).

Affected Systems

All macOS installations running Microsoft Defender for Endpoint that have not yet applied the issued update are potentially affected. The vulnerability is linked to the Microsoft Defender for Endpoint for Mac product and any versions installed prior to the vendor’s fix.

Risk and Exploitability

The CVSS score of 5.5 places the vulnerability in the medium severity range. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild at this time, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is local: an attacker must have some level of permission on the device and can manipulate the OS or Defender processes to create the TOCTOU window. Given the low EPSS and lack of active exploitation reports, the risk remains moderate, but the impact of privilege escalation warrants prompt attention.

Generated by OpenCVE AI on July 31, 2026 at 06:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Defender for Endpoint update for macOS once it is released.
  • Limit administrative privileges for user accounts that are not required to run Defender; enforce least privilege for all local users.
  • Enable macOS System Integrity Protection (SIP) to reduce the ability of local code to modify critical system files or processes that could be used in the race condition.

Generated by OpenCVE AI on July 31, 2026 at 06:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Title Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft defender For Endpoint
Weaknesses CWE-367
CPEs cpe:2.3:a:microsoft:defender_for_endpoint:*:*:*:*:*:macos:*:*
Vendors & Products Microsoft
Microsoft defender For Endpoint
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Defender For Endpoint
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:27:02.732Z

Reserved: 2026-06-19T13:53:31.990Z

Link: CVE-2026-56178

cve-icon Vulnrichment

Updated: 2026-07-14T18:55:35.330Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:30:18Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition