{"record":"Microsoft Defender for Endpoint evidence record","url":"https://nexalign.io/vendors/microsoft-defender-for-endpoint","vendor":{"slug":"microsoft-defender-for-endpoint","name":"Microsoft Defender for Endpoint","domain":"microsoft.com","category":"endpoint-security","categoryLabel":"Endpoint security (EDR and XDR)"},"lastChecked":"2026-07-30T22:17:35.580Z","coverage":{"earliest":"2011-02-25T17:00:00.000Z","latest":"2026-07-16T16:17:29.105Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":34,"kindsOfSource":8,"attributedAdvisories":3,"knownExploited":0,"registerEntriesNotAttributable":7,"practitionerThreads":1,"independentItems":7,"vendorPublishedItems":4,"shareFromSourcesTheVendorDoesNotControl":0.59},"sources":[{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":5,"latest":"2026-05-21T07:35:37.000Z"},{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":2,"latest":"2018-04-04T17:00:00.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":2,"latest":"2026-07-14T18:18:23.917Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":1,"latest":"2021-11-03T00:00:00.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":7,"latest":"2026-07-16T16:17:29.105Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":2,"latest":"2025-08-17T09:48:27.000Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":1,"latest":"2025-12-12T09:53:18.000Z"},{"source":"The vendor's own documentation","operator":"Vendor website, indexed by nexalign","classification":"vendor-controlled","items":14,"latest":"2026-05-21T16:39:21.593Z"}],"advisories":{"shown":3,"total":3,"truncated":false,"items":[{"id":"CVE-2026-56178","description":"Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.","severity":"medium","cvss":5.5,"knownExploited":false,"date":"2026-07-14T18:18:23.917Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-56178"]},{"id":"CVE-2026-45647","description":"Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.","severity":"medium","cvss":5.5,"knownExploited":false,"date":"2026-06-09T17:17:31.797Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-45647"]},{"id":"WID-SEC-2024-3412","description":"Affected products: Microsoft Defender","severity":"high","cvss":9.1,"knownExploited":false,"date":"2024-11-13T09:16:21.663Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3412"]}]},"practitionerThreads":{"shown":1,"total":1,"truncated":false,"items":[{"title":"Microsoft Defender for Endpoint does not create alerts for process hollowing","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1pko33f/microsoft_defender_for_endpoint_does_not_create/","date":"2025-12-12T09:53:18.000Z"}]},"independentCoverage":{"shown":5,"total":7,"truncated":true,"items":[{"title":"Microsoft Defender for Endpoint Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://gartner.com/reviews/market/endpoint-protection-platforms/vendor/microsoft/product/microsoft-defender-for-endpoint","date":null},{"title":"Microsoft Defender for Endpoint vs Symantec Endpoint Security (2026)","host":"peerspot.com","url":"https://www.peerspot.com/products/comparisons/microsoft-defender-for-endpoint_vs_symantec-endpoint-security","date":null},{"title":"Microsoft Defender for Endpoint vs Trellix MOVE AntiVirus (2026)","host":"peerspot.com","url":"https://www.peerspot.com/products/comparisons/microsoft-defender-for-endpoint_vs_trellix-move-antivirus","date":null},{"title":"Microsoft Defender for Endpoint Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/microsoft-defender-for-endpoint","date":null},{"title":"Microsoft Defender for Endpoint vs Trellix Endpoint Security Platform (2026)","host":"peerspot.com","url":"https://www.peerspot.com/products/comparisons/microsoft-defender-for-endpoint_vs_trellix-endpoint-security-platform","date":null}]},"vendorPublished":{"shown":4,"total":4,"truncated":false,"items":[{"title":"ObjectSet.Key Class (Microsoft.SqlServer.Management.Dmf)","url":"https://learn.microsoft.com/en-us/previous-versions/sql/sql-server-2012/cc281991(v=sql.110)","date":"2026-05-21T16:39:21.593Z"},{"title":"MiningServiceCollection.Dispose Method  (Microsoft.AnalysisServices.AdomdServer)","url":"https://learn.microsoft.com/en-us/previous-versions/sql/sql-server-2012/ms131360(v=sql.110)","date":"2026-05-21T16:39:21.324Z"},{"title":"FailedOperationException.Message Property  (Microsoft.SqlServer.Management.Dmf)","url":"https://learn.microsoft.com/en-us/previous-versions/sql/sql-server-2012/bb895580(v=sql.110)","date":"2026-05-21T16:39:21.163Z"},{"title":"NullFacetException Constructor (String, Exception) (Microsoft.SqlServer.Management.Dmf)","url":"https://learn.microsoft.com/en-us/previous-versions/sql/sql-server-2012/bb934828(v=sql.110)","date":"2026-05-21T16:39:21.019Z"}]},"openQuestions":["A further 7 register entries mention Microsoft Defender for Endpoint without naming a product of Microsoft Defender for Endpoint as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}