CVE-2026-54123: Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
Overview
- Severity
- Medium (CVSS 5.5)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- Category
- Information Disclosure
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
Description
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
FAQ
What information could be disclosed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could view Microsoft Defender for Endpoint configuration exclusion settings that are intended to be viewable only by administrators.
Affected Products (1)
System Center
- Microsoft Defender for Endpoint for Mac
Acknowledgments
Abhishek Mundhra with PwC
Revision History
- 2026-08-11: Information published.