Description
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
Published: 2026-08-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Microsoft Malware Protection Engine component of Microsoft Defender, allowing an attacker to gain elevation of privilege within the Defender context. The flaw can be exploited to obtain higher privileges on the host that the malware protection engine operates under, potentially undermining system security. The weakness is associated with common weakness enumerations related to least privilege and authorization mismanagement (CWE-269, CWE-284).

Affected Systems

All Microsoft Defender installations that incorporate the Microsoft Malware Protection Engine are impacted. The CNA lists the product as Microsoft:Microsoft Malware Protection Engine, and no specific version numbers are disclosed, so any Defender deployment that uses this engine component may be susceptible pending confirmation of the affected build by Microsoft.

Risk and Exploitability

The advisory assigns a CVSS score of 7.8, classifying the issue as high severity. The EPSS score is reported as less than 1%, indicating a low likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. The documented description does not specify the detailed attack vector; it only references the “ShieldBreak” flaw. Therefore, the exact prerequisites for exploitation remain unspecified in the advisory, and no proven exploitation method is publicly documented.

Generated by OpenCVE AI on September 3, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Use Microsoft’s update guide to install the latest Microsoft Defender security update that addresses the elevation of privilege flaw.
  • If an update is not yet available, restrict or disable the Microsoft Malware Protection Engine component to prevent the privilege escalation path.
  • Monitor Defender and system logs for unexpected privilege changes or anomalies that could indicate exploitation of the elevation of privilege weakness.

Generated by OpenCVE AI on September 3, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;.

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:microsoft:malware_protection_engine:-:*:*:*:*:*:*:*

Sat, 15 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-732

Fri, 14 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
Title Microsoft Defender Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft malware Protection Engine
CPEs cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft malware Protection Engine
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Microsoft Malware Protection Engine
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-03T21:26:20.768Z

Reserved: 2026-08-03T20:57:58.964Z

Link: CVE-2026-69414

cve-icon Vulnrichment

Updated: 2026-08-17T13:00:46.565Z

cve-icon NVD

Status : Modified

Published: 2026-08-14T22:17:06.810

Modified: 2026-09-03T22:18:19.793

Link: CVE-2026-69414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T23:00:11Z

Weaknesses