AI Stories on SHORT INFO are generated & curated with AI
unverified 16 Jun, 20:22

Microsoft Defender RedSun (CVE-2026-41091) and UnDefend (CVE-2026-45498) zero-days actively exploited; CISA KEV deadline June 3

Every Windows machine running Microsoft Defender $MSFT is exposed until the latest Antimalware Platform update is installed. RedSun (CVE-2026-41091) lets any local user become SYSTEM; UnDefend (CVE-2026-45498) silently blocks Defender updates. Both actively exploited. CISA KEV de

Every Windows machine running Microsoft Defender $MSFT is exposed until the latest Antimalware Platform update is installed. Microsoft confirmed two zero-day vulnerabilities under active attack on May 20 and CISA added both to the Known Exploited Vulnerabilities catalog the same day, giving federal civilian agencies until June 3 to patch. RedSun (CVE-2026-41091, CVSS 7.8) is a privilege-escalation flaw in the Defender scan engine. The engine improperly resolves symbolic links and directory junctions while accessing files at elevated permissions, so any low-privilege local foothold can redirect Defender's writes into protected system directories and gain SYSTEM-level access. UnDefend (CVE-2026-45498, CVSS 4.0) is a denial-of-service flaw that silently blocks Defender from receiving definition updates. The condition triggers without alerting administrators or the user, leaving endpoints unprotected against new threats while appearing to run normally. Security firm Huntress reported exploitation of both flaws together with BlueHammer (CVE-2026-33825), a Defender-adjacent privilege bug patched in the same cycle. Microsoft has shipped fixed releases of the Defender Antimalware Platform: versions 1.1.26040.8 and 4.18.26040.7. The components update automatically on most consumer and managed endpoints, but admins should verify deployment across managed fleets before the CISA deadline. Source: CISA KEV alert, May 20, 2026.

Published on
BlueskyFacebookThreadsX