Vendor
Windows Defender Race Condition (EDB-52612) Leads to Local Privilege Escalation and AV Bypass
1 TTP 3 IOCsA critical local race condition (EDB-52612) exists in Microsoft Windows Defender's MsMpEng.exe, specifically between its cleanup routine (`MpCleanCallbackFunction`) and Volume Shadow Copy creation, allowing Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM and temporary disabling of antivirus protection through a use-after-free vulnerability, with a public exploit demonstrating the risk.
CVE-2026-40369 - Windows Kernel Untrusted Pointer Dereference Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-40369 is an untrusted pointer dereference vulnerability in the Windows Kernel that allows a locally authorized attacker to escalate privileges.
CVE-2026-35415: Windows Storage Spaces Controller Integer Overflow Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-35415 is an integer overflow vulnerability in the Windows Storage Spaces Controller that allows a locally authorized attacker to elevate privileges.
CVE-2026-33841 Heap-Based Buffer Overflow in Windows Kernel Allows Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-33841 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows a locally authorized attacker to elevate privileges.