Microsoft Defender CVEs: CVE-2026-41091 (local privilege escalation) and CVE-2026-45498 (denial of service)

Originally published at: Microsoft Defender CVEs: CVE-2026-41091 (local privilege escalation) and CVE-2026-45498 (denial of service) - ToolsLib Blog

Two Microsoft Defender flaws—CVE-2026-41091 (local privilege escalation via link following) and CVE-2026-45498 (denial of service)—are now listed in NVD and MSRC. Here’s what’s confirmed, what remains unclear, and where to find official guidance.