Heap-based buffer overflow in Microsoft Malware Protection Engine - CVE-2026-45584
Published: May 21, 2026
Microsoft Malware Protection Engine
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker can pass a specially crafted file to the system, which once scanned can trigger a heap-based buffer overflow and remote code execution
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.