CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
— CISA
Microsoft Defender Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.18.26030.3011
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33825?
CVE-2026-33825 is rated as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2026-33825?
To fix CVE-2026-33825, ensure that Microsoft Defender is updated to the latest version as released by Microsoft.
What systems are affected by CVE-2026-33825?
CVE-2026-33825 affects multiple versions of Microsoft Defender and the Defender Antimalware Platform.
Can CVE-2026-33825 be exploited remotely?
No, CVE-2026-33825 requires local access to the system in order to be exploited.
What are the potential impacts of CVE-2026-33825?
The potential impacts of CVE-2026-33825 include unauthorized access and control over system resources by an attacker.