Defender
by Microsoft
CVEs (49)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-33825 | Hig | 0.69 | 7.8 | 0.07 | KEV | Apr 14, 2026 | Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | |
| CVE-2021-1647 | Hig | 0.66 | 7.8 | 0.39 | KEV | Jan 12, 2021 | Microsoft Defender Remote Code Execution Vulnerability | |
| CVE-2021-42313 | Cri | 0.65 | 10.0 | 0.04 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-42311 | Cri | 0.65 | 10.0 | 0.04 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2026-41091 | Hig | 0.63 | 7.8 | 0.10 | KEV | May 20, 2026 | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | |
| CVE-2017-0290 | Hig | 0.60 | 7.8 | 0.77 | May 9, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server… | ||
| CVE-2024-38089 | Cri | 0.59 | 9.1 | 0.01 | Jul 9, 2024 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||
| CVE-2021-43882 | Cri | 0.59 | 9.0 | 0.02 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2024-29053 | Hig | 0.57 | 8.8 | 0.03 | Apr 9, 2024 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2024-21323 | Hig | 0.57 | 8.8 | 0.03 | Apr 9, 2024 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-42315 | Hig | 0.57 | 8.8 | 0.02 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-42314 | Hig | 0.57 | 8.8 | 0.02 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-41365 | Hig | 0.57 | 8.8 | 0.03 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2025-62459 | Hig | 0.54 | 8.3 | 0.00 | Nov 20, 2025 | Microsoft Defender Portal Spoofing Vulnerability | ||
| CVE-2026-45584 | Hig | 0.53 | 8.1 | 0.01 | May 20, 2026 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. | ||
| CVE-2021-42310 | Hig | 0.53 | 8.1 | 0.02 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2017-11937 | Hig | 0.53 | 7.8 | 0.28 | Dec 7, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and… | ||
| CVE-2017-11940 | Hig | 0.52 | 7.8 | 0.20 | Dec 8, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and… | ||
| CVE-2023-23379 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||
| CVE-2022-23266 | Hig | 0.51 | 7.8 | 0.01 | Mar 9, 2022 | Microsoft Defender for IoT Elevation of Privilege Vulnerability |
- risk 0.69cvss 7.8epss 0.07
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- risk 0.66cvss 7.8epss 0.39
Microsoft Defender Remote Code Execution Vulnerability
- risk 0.65cvss 10.0epss 0.04
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.65cvss 10.0epss 0.04
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.63cvss 7.8epss 0.10
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- risk 0.60cvss 7.8epss 0.77
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server…
- risk 0.59cvss 9.1epss 0.01
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.02
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.54cvss 8.3epss 0.00
Microsoft Defender Portal Spoofing Vulnerability
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.02
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.53cvss 7.8epss 0.28
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and…
- risk 0.52cvss 7.8epss 0.20
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and…
- risk 0.51cvss 7.8epss 0.00
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Page 1 of 3