Elevation of Privilege in Microsoft Defender Malware Protection Engine
Elevation of privilege in Microsoft Defender's Malware Protection Engine (MsMpEng.exe). CVSS 7.8 High. No patch yet; MSRC advisory live and security update in progress.
- Vendor
- Microsoft
- Product
- Microsoft Defender (Malware Protection Engine)
- CVSS
- 7.8
- EPSS (exploit probability)
- N/A
- Status
- unpatched
- Published
CVE-2026-69414 is an elevation of privilege vulnerability in the Microsoft Malware Protection Engine (MsMpEng.exe), the core scanning process in Windows Defender. MsMpEng.exe runs with SYSTEM privileges on Windows machines with real-time protection enabled. An EoP flaw in this component allows an attacker with initial code execution access to escalate to SYSTEM-level privileges.
Microsoft publicly refers to this vulnerability as “ShieldBreak” — a name also applied to CVE-2026-50656, a separate Defender EoP patched in August 2026’s Patch Tuesday. CVE-2026-69414 is a distinct flaw in a different component.
No patch is available as of August 14, 2026. MSRC’s advisory confirms awareness and states a security update is in development. No active exploitation or public proof-of-concept has been confirmed as of initial disclosure.
Affected: Windows systems with Microsoft Defender real-time protection enabled (all editions).
Mitigation (pending patch): Keep Defender Security Intelligence (signature) updates current. Microsoft ships signature database updates continuously and separately from Windows Update; these may include behavioral mitigations ahead of a binary patch. Monitor MSRC’s advisory for patch availability.
