Microsoft Defender Zero-Days: Privilege Escalation & Denial-of-Service [CVE-2026-41091, CVE-2026-45498]
May 21, 2026
Deskripsi
1
| |
|
|
| |
Microsoft merilis patch darurat untuk dua kerentanan zero-day pada Microsoft Defender yang sedang aktif dieksploitasi :
- CVE-2026-41091 — Local Privilege Escalation (LPE) ke SYSTEM melalui improper link resolution before file access (link following) pada Microsoft Malware Protection Engine.
- CVE-2026-45498 — Denial-of-Service (DoS) pada Microsoft Defender Antimalware Platform yang membuat sistem Windows tidak responsif.
Kedua CVE telah masuk Catalog KEV CISA (20 Mei 2026). Instansi pemerintah AS (FCEB) diwajibkan mem-patch sebelum 3 Juni 2026.
|
|
| |
|
|
Metode Serangan
2
| |
|
|
| |
- CVE-2026-41091: Penyerang memanfaatkan kelemahan "link following" pada Malware Protection Engine untuk menaikkan privilege dari user biasa ke SYSTEM — kontrol penuh terhadap endpoint.
- CVE-2026-45498: Penyerang memicu kondisi denial-of-service pada Antimalware Platform, menyebabkan sistem Windows menjadi tidak responsif hingga memerlukan restart.
|
|
| |
|
|
Sistem Terdampak
3
| |
|
|
| |
- Microsoft Malware Protection Engine versi ≤ 1.1.26030.3008
- Microsoft Defender Antimalware Platform versi ≤ 4.18.26030.3011
- Windows endpoints & servers dengan Microsoft Defender aktif
- Produk terkait: System Center Endpoint Protection, Security Essentials
|
|
| |
|
|
Mitigasi
4
| |
|
|
| |
[CRITICAL] Update ke versi aman:
- Malware Protection Engine ≥ 1.1.26040.8
- Defender Antimalware Platform ≥ 4.18.26040.7
Langkah verifikasi update:
- Tekan Win + S → ketik "Security" → buka Windows Security
- Navigasi ke: Virus & threat protection → Protection updates
- Klik "Check for updates"
- Navigasi ke: Settings → About
- Periksa "Antimalware Client Version" — pastikan versi platform dan signature package sudah sesuai atau melebihi versi di atas.
Catatan: Secara default, Microsoft antimalware akan update otomatis. Namun, admin IT harus tetap memverifikasi konfigurasi auto-update aktif, terutama pada sistem kritis.
Untuk organisasi: Prioritaskan patching pada endpoint/server kritis dan ikuti panduan vendor/CISA mengingat kedua CVE sudah masuk KEV dengan eksploitasi aktif.
|
|
| |
|
|
Referensi: ?
1. https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/
2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091
3. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498
4. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
5. https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog