DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-45584PUBLISHED: 2026-05-20
HIGHCVE-2026-45584

Microsoft Defender Malware Protection Engine Heap Buffer Overflow RCE

VENDOR: Microsoft//PRODUCT: Microsoft Defender / Malware Protection Engine
8.1
HIGH
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

A heap-based buffer overflow in the Microsoft Malware Protection Engine allows an unauthenticated remote attacker to execute arbitrary code over a network without user interaction. Patched in the same out-of-band engine update (v1.1.26040.8) as CVE-2026-41091, this vulnerability has not yet had confirmed in-the-wild exploitation but shares the same affected engine version as the actively exploited RedSun/UnDefend chain. Defender's automatic update mechanism delivers the fix on connected endpoints, but organizations should verify fleet-wide update status.

Attack Vector
NETWORK
Attack Complexity
HIGH
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSMicrosoft Malware Protection Engine v1.1.26030.3008 and earlier
  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584
  • https://www.techtimes.com/articles/316957/20260521/microsoft-defender-zero-days-patched-redsun-undefend-exploits-already-used-live-intrusions.htm
  • https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn