Medium severity6.7NVD Advisory· Published May 13, 2025· Updated Jun 17, 2026
CVE-2025-26684
CVE-2025-26684
Description
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Affected products
3cpe:2.3:a:microsoft:defender_for_endpoint:*:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:microsoft:defender_for_endpoint:*:*:*:*:*:linux:*:*range: <101.25032.0008
- (no CPE)
- (no CPE)range: 101.0.0
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26684nvdVendor Advisory
News mentions
0No linked articles in our index yet.