Skip to content
Threat Feed

Vendor

Microsoft Corporation

4 briefs RSS
critical advisory

Windows Defender Race Condition (EDB-52612) Leads to Local Privilege Escalation and AV Bypass

A critical local race condition (EDB-52612) exists in Microsoft Windows Defender's MsMpEng.exe, specifically between its cleanup routine (`MpCleanCallbackFunction`) and Volume Shadow Copy creation, allowing Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM and temporary disabling of antivirus protection through a use-after-free vulnerability, with a public exploit demonstrating the risk.

Windows Defender Antivirus local-privilege-escalation race-condition windows-defender exploit-db vulnerability endpoint
1t 3i
high advisory

CVE-2026-40369 - Windows Kernel Untrusted Pointer Dereference Privilege Escalation

CVE-2026-40369 is an untrusted pointer dereference vulnerability in the Windows Kernel that allows a locally authorized attacker to escalate privileges.

Windows Kernel privilege-escalation windows-kernel cve
2r 1t 1c
high threat

CVE-2026-35415: Windows Storage Spaces Controller Integer Overflow Privilege Escalation

CVE-2026-35415 is an integer overflow vulnerability in the Windows Storage Spaces Controller that allows a locally authorized attacker to elevate privileges.

exploited Windows Storage Spaces Controller cve vulnerability privilege-escalation windows
2r 1t 1c
high advisory

CVE-2026-33841 Heap-Based Buffer Overflow in Windows Kernel Allows Privilege Escalation

CVE-2026-33841 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows a locally authorized attacker to elevate privileges.

Windows Kernel cve-2026-33841 privilege-escalation windows
2r 1t 1c