{"dataType": "CVE_RECORD", "containers": {"cna": {"metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}}], "affected": [{"cpes": ["cpe:2.3:a:microsoft:defender_antimalware_platform:*:*:*:*:*:*:*:*"], "vendor": "microsoft", "product": "defender_antimalware_platform", "versions": [{"status": "affected", "version": "0", "lessThan": "4.18.26030.3011", "versionType": "custom"}], "defaultStatus": "unaffected"}], "references": [{"url": "https://www.huntress.com/blog/nightmare-eclipse-intrusion", "tags": ["third-party-advisory"]}, {"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825", "tags": ["vendor-advisory"]}, {"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33825", "tags": ["x_us-government-resource"]}], "descriptions": [{"lang": "en", "value": "Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally."}], "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-1220", "description": "CWE-1220"}]}], "providerMetadata": {"orgId": "00000000-0000-4000-A000-000000000003", "shortName": "nvd", "dateUpdated": "2026-04-14T18:17:35Z", "x_subShortName": "nvd"}}}, "cveMetadata": {"cveId": "CVE-2026-33825", "state": "PUBLISHED", "dateUpdated": "2026-04-23T17:26:30Z", "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8", "datePublished": "2026-04-14T18:17:35Z", "assignerShortName": "microsoft"}, "dataVersion": "5.0"}