Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Defender.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-41091HIGH | Microsoft Defender Elevation of Privilege VulnerabilityImproper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. CWE-59May 20, 2026 | CVSS7.8v3.1 | EPSS9.64% | PoCs5 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45498MEDIUM | Microsoft Defender Denial of Service VulnerabilityMicrosoft Defender Denial of Service Vulnerability CWE-400May 20, 2026 | CVSS4.0v3.1 | EPSS63.1% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33825HIGH | Microsoft Defender Elevation of Privilege VulnerabilityInsufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. CWE-1220Apr 14, 2026 | CVSS7.8v3.1 | EPSS6.75% | PoCs5 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2022-44698MEDIUM | Windows SmartScreen Security Feature Bypass VulnerabilityWindows SmartScreen Security Feature Bypass Vulnerability. | CVSS5.4v3.1 | EPSS76.3% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-1647HIGH | Microsoft Defender Remote Code Execution VulnerabilityMicrosoft Defender Remote Code Execution Vulnerability | CVSS7.8v3.1 | EPSS39.4% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |