• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-69414: elevation of privilege in Microsoft Microsoft Malware Protection Engine

A local attacker with a low-privilege account can elevate privileges in Microsoft Malware Protection Engine (CVE-2026-69414). The flaw affects versions 1.1.0.0 through before 1.1.26080.3; 1.1.26080.3 contains the fix. Exploitation requires local access and does not require user interaction, allowing code or actions to run with higher privileges on affected hosts.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00327
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code is available, so prioritize updating to the fixed build 1.1.26080.3 or apply vendor guidance immediately.

What is CVE-2026-69414?

A local attacker with a low-privilege account can elevate privileges in Microsoft Malware Protection Engine (CVE-2026-69414). The flaw affects versions 1.1.0.0 through before 1.1.26080.3; 1.1.26080.3 contains the fix. Exploitation requires local access and does not require user interaction, allowing code or actions to run with higher privileges on affected hosts.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Microsoft Malware Protection Engine are affected?

BRANCHAFFECTEDFIXED
1.x1.1.0.0 – before 1.1.26080.31.1.26080.3

Is CVE-2026-69414 being exploited?

Public exploit code is available.

How to fix CVE-2026-69414

  1. Install the fixed Microsoft Malware Protection Engine build 1.1.26080.3.
  2. If you cannot patch immediately, restrict local access to systems running the engine and limit accounts with local logon rights.
  3. Monitor endpoint logs and telemetry for suspicious privilege escalation behavior related to the engine.
  4. Follow Microsoft guidance for any additional configuration or mitigation steps.

Frequently asked questions

Is CVE-2026-69414 being actively exploited?

Public exploit code is available for CVE-2026-69414, increasing the risk of active exploitation.

Which Microsoft Malware Protection Engine versions are affected by CVE-2026-69414?

Versions 1.1.0.0 through before 1.1.26080.3 are affected; the fix is in 1.1.26080.3.

Is there a patch for CVE-2026-69414?

Yes. Microsoft released a fixed build: 1.1.26080.3.

Does CVE-2026-69414 require authentication?

Yes. Exploitation requires local access with a low-privilege account; no user interaction is required.

References