CVE-2026-54123

EUVD-2026-56418
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38.71%
Affected Products (NVD)
VendorProductVersion
microsoftdefender_for_endpoint
101.0.0 ≤
𝑥
< 101.26042.0020
𝑥
= Vulnerable software versions