CVE-2026-45647: Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
Overview
- Severity
- Medium (CVSS 5.5)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Jun
- Released
- 2026-06-09
Description
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Affected Products (1)
System Center
- Microsoft Defender for Endpoint for Mac
Acknowledgments
<a href="https://www.linkedin.com/in/mihalis-h-551323164">Mihalis Haatainen</a> with <a href="https://bountyy.fi/">Bountyy Oy</a>
Revision History
- 2026-06-09: Information published.