Actively exploited Microsoft Defender flaw grants SYSTEM access

Microsoft has disclosed CVE-2026-41091, a Microsoft Defender privilege elevation vulnerability that is actively exploited in the wild. The flaw stems from improper link handling and can allow an attacker to obtain SYSTEM-level access.

CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, reinforcing the urgency of updating affected systems immediately.

What this means for your business

The vulnerability sits in the security product itself, which by design runs with high privileges on every client. That makes the attack efficient and gives the attacker full control of the machine. When CISA lists something as actively exploited, the window to act is short. For organisations under NIS2 this is also an example of why remediation deadlines should be a governance parameter rather than a case-by-case judgement.

Berigo recommends

  • Verify that the update has actually reached every client, not merely that it was approved in the management tool.
  • Set a fixed remediation deadline for vulnerabilities listed in the CISA catalog, and measure compliance against it.
  • Look for unexpected SYSTEM-level activity in the period before the update was deployed.
  • Report status on actively exploited vulnerabilities to management monthly.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch