CVE-2026-33825 Details
Description
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
A vulnerability in Microsoft Defender has been identified, allowing authorized attackers to elevate privileges locally. This issue arises from an insufficient granularity of access control, which can be exploited to gain SYSTEM privileges. The vulnerability is present in the Windows Defender Antimalware Platform, specifically in version 4.18.26020.6, and was addressed in version 4.18.26030.3011.
Users should ensure that they have installed the latest version of the Microsoft Defender Antimalware Platform and that malware definition updates are being actively downloaded and installed. For enterprise deployments, it is recommended to verify that the automatic deployment of Defender updates is functioning as expected.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33825 | CISA-ADP | US Government Resource |
| https://www.huntress.com/blog/nightmare-eclipse-intrusion | CISA-ADP | Third Party Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825 | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Microsoft Defender Insufficient Granularity of Access Control Vulnerability | Apr 22, 2026 | May 6, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1220 | Insufficient Granularity of Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft defender antimalware platform | < 4.18.26030.3011 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Modified Analysis | [email protected] |
| Apr 22, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2026 | New CVE Received | [email protected] |