SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-56178

MEDIUM · CVSS 5.5 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Microsoft Defender for Endpoint is vulnerable to a time-of-check time-of-use (TOCTOU) race condition, enabling authorized attackers to elevate their privileges locally. This vulnerability could allow attackers to gain unauthorized access to sensitive system functions or data. Organizations using Microsoft Defender for Endpoint should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-56178
Severity
MEDIUM
CVSS
5.5
EPSS
0.17%
Microsoft

Original NVD Description

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)