CVE-2026-33825
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- Affected products
- Defender
- Microsoft Defender Antimalware Platform
- < 4.18.26030.3011
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 6.7% (93th percentile)
- Weakness
- CWE-1220
- NVD status
- Analyzed
- Published
- 2026-04-14
CVE-2026-33825 at NVD
4 known exploits for CVE-2026-33825
Proof-of-concept code and exploit modules indexed by Sploitus