Medium severity6.7NVD Advisory· Published May 13, 2025· Updated Jun 17, 2026
CVE-2025-26684
CVE-2025-26684
Description
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Affected products
3101.0.0+ 2 more
- (no CPE)range: 101.0.0
- (no CPE)
- cpe:2.3:a:microsoft:defender_for_endpoint:*:*:*:*:*:linux:*:*range: <101.25032.0008
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26684nvdVendor Advisory
News mentions
0No linked articles in our index yet.