Overview
What is CVE-2026-41091?
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Microsoft Defender Link Following Vulnerability
CISA lists CVE-2026-41091 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft Defender.
Public exploit: Not collected. Review the linked vendor advisory and apply the mitigation or fixed release for your affected product.
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.