Advisory

May 21, 2026

 

Deskripsi

1

 

     
 

Microsoft merilis patch darurat untuk dua kerentanan zero-day pada Microsoft Defender yang sedang aktif dieksploitasi :

  • CVE-2026-41091 — Local Privilege Escalation (LPE) ke SYSTEM melalui improper link resolution before file access (link following) pada Microsoft Malware Protection Engine.
  • CVE-2026-45498 — Denial-of-Service (DoS) pada Microsoft Defender Antimalware Platform yang membuat sistem Windows tidak responsif.

Kedua CVE telah masuk Catalog KEV CISA (20 Mei 2026). Instansi pemerintah AS  (FCEB) diwajibkan mem-patch sebelum 3 Juni 2026.

 
     

 

 

Metode Serangan

2

 

     
 
  1. CVE-2026-41091: Penyerang memanfaatkan kelemahan "link following" pada  Malware Protection Engine untuk menaikkan privilege dari user biasa ke SYSTEM — kontrol penuh terhadap endpoint.
  2. CVE-2026-45498: Penyerang memicu kondisi denial-of-service pada   Antimalware Platform, menyebabkan sistem Windows menjadi tidak responsif hingga memerlukan restart.
 
     

 

 

Sistem Terdampak

3

 

     
 
  • Microsoft Malware Protection Engine versi ≤ 1.1.26030.3008
  • Microsoft Defender Antimalware Platform versi ≤ 4.18.26030.3011
  • Windows endpoints & servers dengan Microsoft Defender aktif
  • Produk terkait: System Center Endpoint Protection, Security Essentials
 
     

 

 

Mitigasi

4

 

     
 

 [CRITICAL] Update ke versi aman:

  • Malware Protection Engine ≥ 1.1.26040.8
  • Defender Antimalware Platform ≥ 4.18.26040.7

Langkah verifikasi update:

  1. Tekan Win + S → ketik "Security" → buka Windows Security
  2. Navigasi ke: Virus & threat protection → Protection updates
  3. Klik "Check for updates"
  4. Navigasi ke: Settings → About
  5. Periksa "Antimalware Client Version" — pastikan versi platform dan signature package sudah sesuai atau melebihi versi di atas.

Catatan: Secara default, Microsoft antimalware akan update otomatis. Namun, admin IT harus tetap memverifikasi konfigurasi auto-update aktif, terutama pada sistem kritis.

Untuk organisasi: Prioritaskan patching pada endpoint/server kritis dan ikuti panduan vendor/CISA mengingat kedua CVE sudah masuk KEV dengan eksploitasi aktif.

 
     

 

 

 

Referensi: ?

1. https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/

2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091

3. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498

4. https://www.cisa.gov/known-exploited-vulnerabilities-catalog 

5. https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog 

 

 

Categories


Categories



Recent posts