According to Qualys, as of yesterday (9/3) there is still no patch. CVE-2026-69414 abuses MS Defender itself for privilege escalation to NT AUTHORITY\SYSTEM
On Sep 4, 2026 12:38 PM, ThePsyko sensed a disturbance and said:
> According to Qualys, as of yesterday (9/3) there is still no patch.
> CVE-2026-69414 abuses MS Defender itself for privilege escalation to NT
> AUTHORITY\SYSTEM
>
> https://rootbadger.com/shortened/xg0tbr8p3 ath-through-microsoft-defender/
People still use that?
--
Darth Yoda
"Debugging the galaxy, one bite at a time."
> On Sep 4, 2026 12:38 PM, ThePsyko sensed a disturbance and said:
>> According to Qualys, as of yesterday (9/3) there is still no patch.
>> CVE-2026-69414 abuses MS Defender itself for privilege escalation to NT
>> AUTHORITY\SYSTEM https://rootbadger.com/shortened/krost8jst p
>> ath-through-microsoft-defender/
>
> People still use that?
It has come a long way over the past decade. I have clients that use the ATP Defender exclusively and it does just as good a job as SentinelOne or Crowdstrike (although I always recommend clients stack em and use Defender with one of the other two since it will automatically go into passive mode when it detects another EDR on the system)
On Sep 4, 2026 1:16 PM, ThePsyko sensed a disturbance and said:
> [quoted text trimmed to the last 100 words] a disturbance and said:
>>> According to Qualys, as of yesterday (9/3) there is still no patch.
>>> CVE-2026-69414 abuses MS Defender itself for privilege escalation to NT
>>> AUTHORITY\SYSTEM https://rootbadger.com/shortened/8iovagrxl
>>>
>>> p ath-through-microsoft-defender/
>>
>> People still use that?
>
> It has come a long way over the past decade. I have clients that use the ATP
> Defender exclusively and it does just as good a job as SentinelOne or
> Crowdstrike (although I always recommend clients stack em and use Defender
> with one of the other two since it will automatically go into passive mode
> when it detects another EDR on the system)
I am on the Linux side. ITP and pf FTW.
--
Darth Yoda
"Debugging the galaxy, one bite at a time."
RootBadger's Android app is now on Google Play. If you would like to help with testing and release
checks, enter the Gmail address you use for Google Play and we will add you to the tester list.
You will receive a Play Store link. Keep it handy for updates.