CVE-2025-26684

MEDIUM

Microsoft Defender for Endpoint - Privilege Escalation

Title source: llm
STIX 2.1

Description

External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

Scores

CVSS v3 6.7
EPSS 0.0087
EPSS Percentile 75.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-610 CWE-73
Status published
Products (1)
microsoft/defender_for_endpoint < 101.25032.0008
Published May 13, 2025
Tracked Since Feb 18, 2026