Home
HIGH: 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 101.0.0 (custom) before 1.0.9.0
affected
Description
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.
Problem types
CWE-94: Improper Control of Generation of Code ('Code Injection')
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21537 (Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability)