6 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-33825 is a high-severity elevation of privilege vulnerability in Microsoft Defender caused by insufficient granularity of access control. The flaw allows an attacker with local access to elevate privileges on the affected system.
Exploitation requires prior access, but once achieved, attackers may gain elevated permissions, access sensitive data, modify security configurations, and interfere with endpoint protection mechanisms. This can enable persistence and deeper compromise of the affected device.
Public proof-of-concept code is available, and exploitation has been observed in the wild prior to patch release.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Elevation of Privilege Vulnerability in Microsoft Defender
Identifier: CVE-2026-33825
CVSS Score: 7.8 (High, CVSS v3.1)
PoC or Exploitation:
Public proof-of-concept code is available and exploitation has been observed in the wild prior to patch release.
Update/ Patch:
Mitigation Recommendation: