Impact
This vulnerability resides in the Microsoft Malware Protection Engine component of Microsoft Defender, allowing an attacker to gain elevation of privilege within the Defender context. The flaw can be exploited to obtain higher privileges on the host that the malware protection engine operates under, potentially undermining system security. The weakness is associated with common weakness enumerations related to least privilege and authorization mismanagement (CWE-269, CWE-284).
Affected Systems
All Microsoft Defender installations that incorporate the Microsoft Malware Protection Engine are impacted. The CNA lists the product as Microsoft:Microsoft Malware Protection Engine, and no specific version numbers are disclosed, so any Defender deployment that uses this engine component may be susceptible pending confirmation of the affected build by Microsoft.
Risk and Exploitability
The advisory assigns a CVSS score of 7.8, classifying the issue as high severity. The EPSS score is reported as less than 1%, indicating a low likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. The documented description does not specify the detailed attack vector; it only references the “ShieldBreak” flaw. Therefore, the exact prerequisites for exploitation remain unspecified in the advisory, and no proven exploitation method is publicly documented.
OpenCVE Enrichment