Microsoft patched two actively exploited vulnerabilities in Microsoft Defender and related protection components, including CVE-2026-41091, a high-severity local privilege escalation flaw that can give an attacker NT AUTHORITY\SYSTEM privileges, and CVE-2026-45498, a medium-severity denial-of-service issue that can make Defender unavailable. The affected products include Microsoft Malware Protection Engine version 1.1.26030.3008 and earlier and Microsoft Defender Antimalware Platform version 4.18.26030.3011 and earlier, and both CVEs were added to CISA’s Known Exploited Vulnerabilities catalog due to active exploitation in the wild.
Technical analysis of CVE-2026-41091, dubbed RedSun, says the bug lies in Windows Defender’s file remediation workflow when it processes malicious files marked as Cloud Files placeholders. A standard user can abuse Defender’s SYSTEM-level file operations, together with NTFS junctions and oplocks, to redirect a privileged write into C:\Windows\System32, plant a malicious binary such as TieringEngineService.exe, and then trigger execution through Storage Tiers Management COM activation to obtain a SYSTEM shell. Microsoft said the issues were fixed through automatic updates and urged organizations that disable auto-updates to manually update Defender and any products using the same engine and platform components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A Calif blog post analyzed the RedSun exploit for CVE-2026-41091, describing how Windows Defender's remediation workflow could be abused to gain arbitrary writes into System32 and execute code as NT AUTHORITY\SYSTEM. The write-up attributed discovery of the flaw to Nightmare Eclipse and documented a six-stage exploit chain involving Cloud Files placeholders, NTFS junctions, oplocks, and COM activation.
CISA added both Microsoft Defender vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating they were being actively exploited in the wild. The listing elevated the significance of the flaws beyond Microsoft's patching notice.
Microsoft addressed CVE-2026-41091, a local privilege escalation flaw, and CVE-2026-45498, a denial-of-service flaw, in Microsoft Defender and related protection components via automatic updates. CSIRT.SK reported the fixes affect Malware Protection Engine version 1.1.26030.3008 and earlier and Defender Antimalware Platform version 4.18.26030.3011 and earlier.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
blog.calif.io
Open sourcecsirt.sk
Open sourcecve.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.