Microsoft Defender Heap-Based Buffer Overflow Vulnerability Allowing Remote Code Execution

Vulnerability

A heap-based buffer overflow vulnerability has been identified in Microsoft Defender. This vulnerability allows an unauthorized attacker to execute code remotely over a network. It affects all supported versions of Windows where Microsoft Defender is installed and active by default. The vulnerability arises from the Microsoft Malware Protection Engine, which provides scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Remediation

The vulnerability has been addressed in version 1.1.26040.8 of the Microsoft Malware Protection Engine. Instructions for managing updates in Microsoft Defender Antivirus can be found in the Microsoft Defender Antivirus Update Management documentation.

Added: May 20, 2026, 1:21 PM
Updated: May 20, 2026, 1:21 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
3.6
remediation
7.7
relevance
8.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.