CVE-2026-41091
KEV High · CVSS 7.8- CVSS
- 7.8
- nvd
- EPSS
- —
- KEV
- Listed
- 2026-05-20
- Class
- other
- CWE-59
Description
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
References
Status: profiled · ingested 2026-07-24T12:00:18.000Z