CVE-2026-54123
- EPSS 0.44%
- Veröffentlicht 11.08.2026 17:04:46
- Zuletzt bearbeitet 17.08.2026 12:06:36
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
- EPSS 0.17%
- Veröffentlicht 14.07.2026 17:09:24
- Zuletzt bearbeitet 22.07.2026 16:34:23
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
- EPSS 0.19%
- Veröffentlicht 14.07.2026 17:08:10
- Zuletzt bearbeitet 22.07.2026 16:35:50
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2026-50657
- EPSS 0.44%
- Veröffentlicht 14.07.2026 17:08:09
- Zuletzt bearbeitet 22.07.2026 16:40:39
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
- EPSS 0.22%
- Veröffentlicht 09.06.2026 17:17:31
- Zuletzt bearbeitet 23.07.2026 08:10:00
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2026-21537
- EPSS 0.53%
- Veröffentlicht 10.02.2026 18:16:35
- Zuletzt bearbeitet 11.02.2026 21:50:25
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.
CVE-2025-59497
- EPSS 0.19%
- Veröffentlicht 14.10.2025 17:01:48
- Zuletzt bearbeitet 30.09.2026 23:10:00
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.
CVE-2025-47161
- EPSS 0.8%
- Veröffentlicht 15.05.2025 19:21:43
- Zuletzt bearbeitet 08.07.2025 16:15:57
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2025-26684
- EPSS 0.42%
- Veröffentlicht 13.05.2025 16:58:26
- Zuletzt bearbeitet 19.05.2025 18:22:41
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2024-49071
- EPSS 1.08%
- Veröffentlicht 12.12.2024 19:15:09
- Zuletzt bearbeitet 10.01.2025 18:24:41
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.