Microsoft Defender Insufficient Granularity of Access Control Vulnerability
High Listed in CISA KEV
Summary
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Microsoft:Defender
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2026-33825 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825 reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV