CVE-2026-45584High· 8.1▾ MidnightPoC availableHeap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
1 GitHub repo
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
malware_protection_engine >= 1.1.26030.3008, < 1.1.26040.8Upgrade past the affected range:
malware_protection_engine 1.1.26040.8Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-20820High· 7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2024-30085High· 7.8Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-24993High· 7.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-69486High· 8.8Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
GHSA-mqvm-gmc4-6rv2High· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability