Home/Product/microsoft defender for endpoint
Product

microsoft defender for endpoint

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-21537
all versions
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execu
8.8HIGH
CVE-2025-59497
< 101.25032.0010
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service lo
7.0HIGH
CVE-2025-47161
< 101.25022.0002
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
7.8HIGH
CVE-2025-26684
< 101.25032.0008
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges local
6.7MEDIUM
CVE-2024-49071
all versions
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an a
6.5MEDIUM
CVE-2024-49057
< 1.0.7128.0101
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
8.1HIGH
CVE-2024-43614
< 101.24052.0002
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
5.5MEDIUM
CVE-2024-21315
< 10.0.25398.531
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-35828
all versions
Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-33637
all versions
Microsoft Defender for Endpoint Tampering Vulnerability
6.5MEDIUM
CVE-2022-23278
all versions
Microsoft Defender for Endpoint Spoofing Vulnerability
5.9MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin