Input validation error in Windows Defender - CVE-2026-45498
Published: May 21, 2026
Windows Defender
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass a specially crafted file to the application and temporary disable antimalware protection.
Note, the vulnerability is being actively exploited in the wild.