top of page

CISA warns of Zero-day vulnerabilities in Windows Defender: Microsoft releases emergency patches

Updated: May 27

The widely used security application, Microsoft Defender, has recently logged two highly critical "zero-day" vulnerabilities (software flaws that are unknown or unpatched before being actively exploited). In response to this imminent threat, Microsoft has swiftly rolled out emergency fixes.

Concurrently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added these flaws to its catalog of high-risk vulnerabilities, following confirmed reports of active exploitation in the wild.

The grave dangers of the new flaws

These two vulnerabilities reside within the core components responsible for file scanning and malware prevention in Microsoft Defender. If successfully exploited, a local attacker with direct access to the device could escalate their privileges to the system level-the highest tier of system authority-or crash the anti-malware service entirely.

The dangers posed by two security vulnerabilities in Windows Defender
The dangers posed by two security vulnerabilities in Windows Defender

In a malware attack, both scenarios offer substantial advantages to cybercriminals. First, they can disable the built-in security shield to evade detection-especially dangerous if the system relies solely on Microsoft’s endpoint protection-and subsequently gain full control over the compromised computer.

Origin and affected system components

According to cybersecurity experts, these two vulnerabilities are believed to power the "RedSun" and "UnDefend" exploits published on GitHub last month by a disgruntled researcher going by the handle "Nightmare Eclipse." While this connection is highly plausible, Microsoft has not officially mentioned these exploit names in its security advisories.

The technical breakdown of the two vulnerabilities includes:

  • CVE-2026-41091 Vulnerability: Located within the mpengine.dll file, which belongs to the Microsoft Malware Protection Engine (MPE). This critical component is responsible for file scanning, malware detection, and remediation across a wide range of the company's security products, including Microsoft Defender, Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection, and Microsoft Security Essentials. The flaw is described as an improper link resolution before file access, which leads to unintended consequences when the system processes paths or shortcuts.

  • CVE-2026-45498 Vulnerability: Tied to the Microsoft Defender Antimalware Platform (MsMpEng.exe). Much like the MPE component mentioned above, this platform works alongside kernel-mode drivers to monitor and protect computers in real-time, and is deeply integrated into Microsoft’s various other endpoint protection solutions.

Actionable steps: how to protect your devices

Typically, Microsoft pushes malware definition updates about three times a day. However, core platform components such as mpengine.dll and MsMpEng.exe are generally updated only once a month, or on an as-needed basis for critical emergencies.

Therefore, both individual users and system administrators are strongly urged to manually trigger an update check within their respective security products. Ensure your systems are running the following secure versions or newer:

  • Malware Protection Engine (MPE): Version 1.1.26040.8 or newer

  • Microsoft Defender Antimalware Platform: Version 4.18.26040.7 or newer

Proactively verifying and updating your cybersecurity software is paramount to safeguarding sensitive data against sophisticated zero-day threats. Users should perform this upgrade as soon as possible to ensure their endpoint security remains robust and effective.

IPSIP Vietnam delivers leading cybersecurity solutions for enterprises

As the surge of zero-day vulnerabilities threatens to completely obliterate traditional security boundaries, building and maintaining a sophisticated defense infrastructure internally can rapidly drain organizational resources. Rooted in over 15 years of rich experience spanning back to France, the IPSIP Vietnam ecosystem positions itself as a premier strategic partner. We offer a sharp, comprehensive understanding of risk management and autonomous malware interception tailored for the digital era.

IPSIP Vietnam cybersecurity solution
IPSIP Vietnam cybersecurity solutions

IPSIP Vietnam’s management and monitoring systems have successfully cleared rigorous audits to achieve world-class information security certifications, including ISO 27001:2022 and SOC 2 Type II. By providing critical, round-the-clock (24/7) services—such as our Security Operations Center (SOC), Network Operations Center (NOC), and a dedicated IT Support/Helpdesk squad—IPSIP guarantees immediate response and mitigation against any intrusion attempt, day or night. Partnering with our elite technical experts allows businesses to completely eliminate compliance and legal risks, freeing up vital resources to focus on growth objectives.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page