Link following in Microsoft Malware Protection Engine - CVE-2026-41091

 

Link following in Microsoft Malware Protection Engine - CVE-2026-41091

Published: May 21, 2026 / Updated: August 14, 2026


Vulnerability identifier: #VU132035
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41091
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an insecure link following issue. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with elevated privileges.

Note, the vulnerability is being actively exploited in the wild. 


Affected software

Microsoft Malware Protection Engine

How to mitigate CVE-2026-41091

Install updates from vendor's website.

Microsoft Malware Protection Engine - update to 1.1.26040.8

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins