CVE-2026-69414: Microsoft Defender Elevation of Privilege Vulnerability
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
CSIRTS triage
- What
- An elevation of privilege vulnerability exists in the Microsoft Malware Protection Engine that allows attackers to gain higher privileges on affected systems.
- Who is affected
- All users running Microsoft Defender are potentially affected until a patch is released.
- Urgency
- High severity (CVSS 7.8) with no current public exploitation reported, but remediation should be prioritized once available.
- Action
- Apply the Microsoft security update for the Malware Protection Engine when released; check Microsoft Security Update Guide for specific patch details.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Microsoft Defender
Get an email when a new Microsoft Defender advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-694140.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69414 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Microsoft Defender Elevation
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-69414: Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in …nvd · 2026-08-14
- mediumCVE-2026-56178: Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an…nvd · 2026-07-14
- highCVE-2026-50658: Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized a…nvd · 2026-07-14
- highCVE-2026-50658: Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
- mediumCVE-2026-56178: Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
- highCVE-2026-50656: Microsoft Defender Elevation of Privilege Vulnerabilitymsrc · 2026-06-09
More from Microsoft Security Response Center
- highCVE-2026-70130: Microsoft Office Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-70354: .NET Core Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-68792: Microsoft Office Elevation of Privilege Vulnerability2026-08-11
- highCVE-2026-66807: Microsoft Office Graphics Component Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-64909: Microsoft Office Remote Code Execution Vulnerability2026-08-11