CVE-2026-33825CISA KEV: Actively Exploited

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Published Apr 22, 2026·Updated Apr 22, 2026

Description

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

Public Exploits & PoCs4 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free