Overview
What is CVE-2026-33825?
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
CISA lists CVE-2026-33825 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft Defender.
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.