Vulnerability record · CVE-2026-33825 · published 14 April 2026
CVE-2026-33825: Microsoft Defender Antimalware Platform access control flaw allows local privilege escalation
Microsoft · Defender Antimalware Platform
Microsoft Defender Antimalware Platform has insufficient granularity of access control (CWE-1220), letting an authorized local attacker elevate privileges. The flaw is rated CVSS 7.8 (HIGH) and is listed in CISA KEV with known ransomware campaign use, so it matters to any Windows estate running Defender.
Description
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with CISA KEV listing, known ransomware campaign use and a near-term remediation deadline make this a high-priority local privilege escalation.
What it is
Microsoft Defender Antimalware Platform has insufficient granularity of access control (CWE-1220), letting an authorized local attacker elevate privileges. The flaw is rated CVSS 7.8 (HIGH) and is listed in CISA KEV with known ransomware campaign use, so it matters to any Windows estate running Defender.
Impact
An attacker who already holds low-privileged local access can gain elevated privileges on the host, with high impact to confidentiality, integrity and availability. That elevation can be a stepping stone to broader compromise, consistent with its documented use in ransomware campaigns.
Attack surface
Reached locally (AV:L) with low attack complexity and no user interaction (AC:L/UI:N), but it requires the attacker to already be authorized on the system (PR:L). No remote or network vector is described.
Exploitation
CISA added it to KEV on 2026-04-22 with a 2026-05-06 remediation due date and flags known ransomware campaign use, indicating exploitation in the wild. EPSS 30-day probability is 0.06749 (93.6th percentile), and a third-party advisory reference exists.
What to do
- Apply the Microsoft update per the MSRC advisory for CVE-2026-33825 as the first action.
- Follow CISA BOD 22-01 guidance and meet the 2026-05-06 KEV due date; discontinue use of the product if mitigations are unavailable.
- Restrict and monitor local interactive and service accounts to reduce the low-privileged foothold this flaw requires.
- Review Defender platform versioning and ensure the antimalware platform is current across all endpoints.
Detection
- Hunt for unexpected privilege escalation or token manipulation events on hosts running Microsoft Defender.
- Monitor for suspicious processes interacting with Defender platform components or services.
- Correlate local logon and process creation telemetry for low-privileged accounts gaining elevated rights.
- Track KEV-related indicators and the referenced Huntress intrusion reporting for associated activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-33825 to the Known Exploited Vulnerabilities catalog on 22 April 2026 as "Microsoft Defender Insufficient Granularity of Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 6 May 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33825 | US Government Resource |
| https://www.huntress.com/blog/nightmare-eclipse-intrusion | Third Party Advisory |
Track CVE-2026-33825 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-33825), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.