Changeflow GovPing Data Privacy & Cybersecurity Microsoft Defender Privilege Escalation Vulnera...
Priority review Notice Added Final

Microsoft Defender Privilege Escalation Vulnerability WID-SEC-2026-1155

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published
Detected
Email

Summary

CERT-Bund issued security advisory WID-SEC-2026-1155 regarding a privilege escalation vulnerability in Microsoft Defender for Windows. A local attacker can exploit the flaw to elevate their privileges on the affected system. The vulnerability carries a CVSS Base Score of 7.8 (High) and a Temporal Score of 7.4 (High). Remote attack is not possible. No patch or mitigation is currently available as of the advisory date.

Published by CERT-Bund on wid.cert-bund.de . Detected, standardized, and enriched by GovPing. Review our methodology and editorial standards .

What changed

CERT-Bund published advisory WID-SEC-2026-1155 identifying a local privilege escalation vulnerability in Microsoft Defender. The flaw allows an authenticated local attacker to escalate privileges by exploiting the security software itself. With no remote attack vector and a CVSS score of 7.8, organizations running Windows systems with Microsoft Defender should monitor for vendor patches.

Affected parties running Windows environments with Microsoft Defender should prioritize applying vendor-released patches once available and implement compensating controls such as limiting local user privileges until the vulnerability is remediated. Security teams should track the CVE reference and monitor CERT-Bund and Microsoft channels for updated mitigation guidance.

What to do next

  1. Apply security patches when released by Microsoft
  2. Monitor vendor advisories for updates
  3. Review system access controls pending patch deployment

Archived snapshot

Apr 16, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

[WID-SEC-2026-1155] Microsoft Defender: Schwachstelle ermöglicht Privilegieneskalation CVSS Base Score 7.8 (hoch) CVSS Temporal Score 7.4 (hoch) Remoteangriff nein Datum 15.04.2026 Stand 16.04.2026 Mitigation nein

Betroffene Systeme

Betriebssystem

  • Windows

Produktbeschreibung

Microsoft Defender ist eine Software zur Erkennung von schädlicher Software (Malware).

Produkte

15.04.2026
- Microsoft Defender

Angriff

Angriff

Ein lokaler Angreifer kann eine Schwachstelle in Microsoft Defender ausnutzen, um seine Privilegien zu erhöhen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Get daily alerts for CERT-Bund Security Advisories

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
CERT-Bund
Published
April 15th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
WID-SEC-2026-1155

Who this affects

Applies to
Technology companies Government agencies Healthcare providers
Industry sector
5112 Software & Technology
Activity scope
Security vulnerability management Patch management Privilege escalation defense
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software & Technology Government & Public Administration

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!