Microsoft Defender Malware Engine Privilege Escalation LPE | MSSP Advisory
Critical
DateMay 21, 2026
📋Executive Summary
Microsoft patched two zero-day vulnerabilities in Microsoft Defender's malware protection engine that allow local attackers to escalate to system-level privileges or disable the anti-malware service entirely. CISA added both CVE-2026-41091 and CVE-2026-45498 to the KEV catalog after detecting active exploitation in the wild. Security researchers link these flaws to the RedSun and UnDefend exploits published on GitHub last month.
⚠️Why It Matters for MSSPs
Your RMM agents and endpoint management tools likely depend on Windows Defender for baseline protection, and compromised Defender means attackers can disable detection while gaining system access to your management infrastructure. Every client running Windows with default Defender protection faces the same exposure, and if you knew about these actively exploited zero-days but failed to communicate patching urgency, you own the aftermath when their systems get compromised.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.