EXPOSURES › CVE-2026-33825
CVE-2026-33825
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft Defender allows local privilege escalation via insufficient access control granularity, enabling ransomware-linked attackers to bypass security controls.
This critical vulnerability in Microsoft Defender permits authorized attackers to escalate privileges locally, undermining the security posture of DIB organizations relying on Defender for compliance. Because it is actively exploited and linked to ransomware, it poses an immediate threat to data integrity and confidentiality, requiring immediate patching and access control review.
Shame score — A critical, actively exploited vulnerability in a core security product that enables ransomware-linked privilege escalation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |