Defender Vulnerability Remediation
A Windows machine is remediated for the 2026 Defender CVEs when its Defender platform is 4.18.26040.7 or later and its engine is 1.1.26040.8 or later. That applies even when another antivirus (for example CrowdStrike Falcon) is the active protection, because the scanner checks Defender's files, not whether Defender is protecting the machine.
This page covers how to find every affected machine with Tanium, which scenario each one is in, and the fix for each scenario.
Test status
The questions on this page were run in a lab Tanium environment with Windows Server 2016, 2019, 2022, and 2025, Windows 10, and Windows 11 endpoints. Both packages were run locally on Windows 11 Pro to confirm their safety stops (exit code 2). Neither package has been run through a Tanium action against a server yet. Test on one server before deploying wider.
Fix levels
| CVE | Type | Component | Fixed in |
|---|---|---|---|
| CVE-2026-33825 | Elevation of privilege (CISA KEV) | Antimalware Platform | 4.18.26030.3011 |
| CVE-2026-45498 | Denial of service (CISA KEV) | Antimalware Platform | 4.18.26040.7 |
| CVE-2026-41091 | Elevation of privilege (CISA KEV) | Malware Protection Engine | 1.1.26040.8 |
| CVE-2026-45584 | Remote code execution | Malware Protection Engine | 1.1.26040.8 |
Platform 4.18.26040.7 covers both platform CVEs. Engine 1.1.26040.8 covers both engine CVEs. When a new Defender CVE is published, update this table and rerun Find the scope.
Why machines with another antivirus still get flagged
Installing a third-party antivirus does not uninstall Defender. Defender switches to passive or turns off, but its files stay on disk:
| Location | What is there |
|---|---|
C:\Program Files\Windows Defender\ |
The copy that ships with Windows |
C:\ProgramData\Microsoft\Windows Defender\Platform\<version>\ |
One folder per platform update |
C:\ProgramData\Microsoft\Windows Defender\Definition Updates\ |
Engine and signatures |
When the WinDefend service is stopped, Defender stops updating and stops cleaning up its old platform folders. The files fall behind and match the CVE ranges.
In the lab, every machine with WinDefend running was on a fixed platform and kept only two or three recent Platform folders. Every machine with WinDefend stopped was on an old platform and was vulnerable:
| OS | WinDefend | Startup | Platform | Result |
|---|---|---|---|---|
| Windows Server 2019 | Running | Auto | 4.18.26080.4 | Fixed |
| Windows Server 2022 | Running | Auto | 4.18.26090.9 | Fixed |
| Windows Server 2022 | Stopped | Manual | 4.18.25110.6 (3 old folders) | Vulnerable |
| Windows Server 2016 | Stopped | Manual | Built-in copy only, no Platform folder |
Vulnerable |
| Windows 11 | Stopped | Manual | 4.18.24080.9 (3 old folders) | Vulnerable |
Sensors used on this page
| Sensor | What it answers |
|---|---|
| Microsoft Defender AntiMalware Details (built-in) | Engine Version, Product Version (platform), Service Enabled, Service State. Reads versions even when the service is stopped |
| Service Details (built-in) | Service Status and Startup Mode for WinDefend |
| Folder Contents[path] (built-in) | Which platform version folders exist on disk |
| File Exists[path] (built-in) | Whether MsMpEng.exe exists at a given path |
| Registry Value Data[key,value] (built-in) | Whether Defender is turned off by policy |
| Operating System (built-in) | Separates servers from workstations. The fix is different |
| Defender - Computer Status (custom) | Running mode, protection state, tamper protection, signature age. Only answers when WinDefend is running |
Find the scope
Build the target list from Tanium, not from the scanner ticket. Scanners miss machines that were offline, out of scope, or failing credentialed scans, and those machines are just as vulnerable.
Run these in Interact, in the question bar.
1. Versions and service state
Get Computer Name and Operating System and Microsoft Defender AntiMalware Details from all machines with Operating System contains Windows
Any row with Product Version below 4.18.26040.7, or Engine Version below 1.1.26040.8, is in scope.
An Engine Version of 0.0.0.0 usually means the service is not running, not that the engine is missing. An Operating System of Server 2016 with Product Version 0.0.0.0 usually means the built-in copy is still there but has never been updated.
2. Service status and startup mode
Get Computer Name and Operating System and Service Details from all machines with Service Details contains WinDefend
If the results include every service on each machine, type WinDefend in the Filter by text box above the results grid.
3. What is on disk
Get Computer Name and Operating System and Folder Contents[C:\ProgramData\Microsoft\Windows Defender\Platform] and File Exists[C:\Program Files\Windows Defender\MsMpEng.exe] from all machines with Operating System contains Windows
MsMpEng.exe is never directly in C:\ProgramData\Microsoft\Windows Defender\. Check C:\Program Files\Windows Defender\MsMpEng.exe, or a specific version folder such as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MsMpEng.exe.
4. Defender turned off by policy
Get Computer Name and Registry Value Data[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender,DisableAntiSpyware] from all machines with Operating System contains Windows
The sensor takes two parameters, Registry Key and Registry Value. The key works in full form (HKEY_LOCAL_MACHINE\...) or short form (HKLM\...). Use (Default) as the value name to read a key's default value.
It returns five columns (User, Data, Type, Architecture, KeyPath) and two rows per machine, one for the 32-bit registry view and one for the 64-bit view. Read the 64-bit row.
| User column | Data column | What it means |
|---|---|---|
| Key/Value not found | (empty) | Policy is not set. Defender is not turned off by this policy |
| N/A | 0 |
Policy is set but does not turn Defender off |
| N/A | 1 |
Defender is turned off by policy (Group Policy, Intune, or a local setting) |
| N/A on Linux | (empty) | Not a Windows machine. Ignore it |
Keep the with Operating System contains Windows filter. Without it, Linux machines come back as N/A on Linux rows.
5. Protection state
Get Computer Name and Defender - Computer Status from all machines with Operating System contains Windows
Use the results of questions 1 to 4 to place each machine in a scenario below.
Scenarios
The WinDefend service status decides the fix. Match each machine to one row, then follow the fix with that letter.
| # | WinDefend | Startup | Other signs | What it means | Fix |
|---|---|---|---|---|---|
| 1 | Running | Auto | Running Mode Normal, versions at or above fix level |
Defender is active and updating | None. Compliant |
| 2 | Running | Auto | Running Mode Passive or EDR Block Mode, versions at or above fix level |
Another antivirus is primary, Defender is onboarded to Defender for Endpoint and still updating | None. Compliant |
| 3 | Running | Auto | Normal or Passive, platform or engine below fix level | Defender is running but its updates are failing or blocked | A |
| 4 | Running | Auto | Platform at fix level, engine below 1.1.26040.8 |
Security intelligence updates are failing. The engine ships with them | A |
| 5 | Running | Auto | Server 2016, no Platform folder, MsMpEng.exe only in C:\Program Files\Windows Defender\ |
Built-in copy that never received a platform update | A |
| 6 | Stopped | Manual | Windows 10 or 11, another antivirus installed | Windows turned Defender off when the other antivirus registered. Updates stopped | B |
| 7 | Stopped | Manual | Windows Server | Defender turned off on a server. Updates stopped | C, then D if folders remain |
| 8 | Stopped | Disabled | Any, often with DisableAntiSpyware set to 1 |
Defender turned off by policy or by hand. Updates stopped | Server: C then D. Workstation: B |
| 9 | Not present | (none) | No WinDefend service, but folders remain under C:\ProgramData\Microsoft\Windows Defender\Platform\ |
Feature was removed, old files left behind | D |
| 10 | Not present | (none) | No WinDefend service, no MsMpEng.exe, no Platform folder |
Defender is gone. The scanner is matching something else | E |
| 11 | Any | Any | Custom sensor returns Error:, versions show 0.0.0.0 |
Defender can't be read, usually because the service is stopped | Recheck with questions 1 to 3, then use row 6, 7, or 8 |
If a machine has DisableAntiSpyware set to 1, find and change the source of that policy before trying Fix A or B, or the setting comes back at the next policy refresh.
Fixes
Removing Defender is a policy decision
Get approval from your security team before running Fix C or Fix D on any server.
Fix A: Update Defender
Defender is running, so it can take updates. The update path is what is broken.
- Check the update source. If machines use WSUS or another patch tool, confirm these are approved:
- Microsoft Defender Antivirus platform update (KB4052623)
- Definition Updates for Microsoft Defender Antivirus. These carry the engine
- Force an engine and signature update with a package that runs:
- If the platform is still behind, download the KB4052623 x64 platform installer from the Microsoft Update Catalog and deploy it as a package. Confirm the installer name and any switches from the catalog entry before building the package.
- Rerun question 1. Product Version should be at or above
4.18.26040.7and Engine Version at or above1.1.26040.8.
Fix B: Workstation with Defender turned off
Uninstall-WindowsFeature only exists on Windows Server. Defender can't be removed from Windows 10 or 11, so the files have to be updated instead.
- Test the KB4052623 platform installer as a package on one workstation. A platform update may not install while
WinDefendis stopped, so confirm it on one machine first. - Rerun question 1 and question 3 on that machine. A new
4.18.26xxxfolder and a Product Version at or above4.18.26040.7mean it worked. - If the platform update does not install, there are two options. Both need security team approval:
- Onboard the machine to Defender for Endpoint so Defender runs in passive mode and updates itself (scenario 2).
- Document a risk exception: the other antivirus is active,
WinDefendis stopped, and Defender can't be removed from the OS.
- The engine CVEs (CVE-2026-41091 and CVE-2026-45584) usually stay open until Defender is running again, because the engine updates through the service.
Fix C: Remove Defender from a server
- Get approval from the security team.
- Confirm the other antivirus is running, so the server is not left with no protection. For CrowdStrike Falcon: Every target server must come back. If one does not, fix the antivirus first.
- Create the Remove Windows Defender package.
- Deploy it to one server first (see Deploy a package).
- Restart the server in a maintenance window. The script does not restart it.
- After the restart, rerun question 3.
C:\Program Files\Windows Defender\MsMpEng.exeshould return File does not exist. - If folders remain under
C:\ProgramData\Microsoft\Windows Defender\Platform\, run Fix D. - Repeat on the remaining servers.
While waiting for approval, you can try the platform installer from Fix B step 1 to close the platform CVEs. The engine CVEs stay open until removal.
Fix D: Delete leftover platform folders
Use only when the WinDefend service no longer exists (scenario 9, or after Fix C and a restart).
- Create the Remove Defender Platform Leftovers package.
- Deploy it to one machine first. The script stops with exit code
2ifWinDefendstill exists, so it can't break an installed Defender. - Rerun question 3. The
Platformfolder should return Folder does not exist.
Fix E: Scanner flag with no Defender files
- Open the finding in the vulnerability scanner and copy its evidence field (the file path and version it matched).
- Ask Tanium for that exact path:
- If the file does not exist, send the Tanium result to the security team and request a rescan or closure of the finding.
Packages
| Package | Used in | Exit codes |
|---|---|---|
| Remove Windows Defender | Fix C | 0 removed or nothing to remove, 3010 removed and restart required, 1 failed, 2 not a server |
| Remove Defender Platform Leftovers | Fix D | 0 removed or nothing to remove, 1 failed, 2 WinDefend still exists |
Neither script restarts the machine. Both restart themselves as 64-bit PowerShell if the Tanium client starts them as 32-bit.
In Action History, exit codes other than 0 can show as Failed. For 3010, the removal worked and the server needs a restart. For 2, the script stopped on purpose before changing anything.
Create the packages
Menu labels can differ slightly between Tanium versions. Repeat these steps for each package.
- Save the script from Scripts with the file name in the table below.
- In the Tanium Console, go to Administration > Content > Packages.
- Click Create Package.
- Fill in the fields from the table below. Content Set is the content set your team uses for custom content.
- Under Files, click Add, choose Local File, and upload the script.
- Leave Parameters empty. These packages have no parameters.
- Click Save.
| Field | Remove Windows Defender | Remove Defender Platform Leftovers |
|---|---|---|
| Package Display Name | Remove Windows Defender |
Remove Defender Platform Leftovers |
| File | Remove-WindowsDefender.ps1 |
Remove-DefenderPlatformLeftovers.ps1 |
| Command | cmd.exe /d /c powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File Remove-WindowsDefender.ps1 |
cmd.exe /d /c powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File Remove-DefenderPlatformLeftovers.ps1 |
| Command Timeout | 30 minutes. Feature removal can take several minutes on a busy server |
10 minutes |
Deploy a package
- In Interact, ask a question that returns the target servers. Example:
- Select the servers in the results grid.
- Click Deploy Action.
- In Deployment Package, search for and select the package.
- Leave the schedule as a one-time action.
- Click Show preview to continue, review the targets, then click Deploy Action.
View the results
Open the action from Administration > Actions > Action History, select an endpoint, and open its action log. The script output appears between the Command Line line and the Completed line.
Removal that needs a restart (illustrative):
2026-10-08 20:38:40 [INFO] Operating system: Microsoft Windows Server 2022 Datacenter
2026-10-08 20:38:41 [INFO] Removing: Windows-Defender
2026-10-08 20:40:12 [INFO] Removal succeeded. Restart required to finish.
Safety stop on a workstation:
2026-10-08 20:38:40 [INFO] Operating system: Microsoft Windows 11 Pro
2026-10-08 20:38:40 [ERROR] Workstation OS detected. Uninstall-WindowsFeature only exists on Windows Server. Nothing done.
Safety stop when Defender is still installed:
2026-10-08 20:38:41 [INFO] Target folder: 'C:\ProgramData\Microsoft\Windows Defender\Platform'
2026-10-08 20:38:41 [ERROR] WinDefend service still exists. Remove the Defender feature and restart first. Nothing deleted.
For many endpoints, ask the built-in Tanium Action Log sensor with the action ID from the top of the log:
Scripts
<#
.SYNOPSIS
Removes the Microsoft Defender Antivirus feature from Windows Server. Built for a Tanium package.
.DESCRIPTION
Tanium package command:
cmd.exe /d /c powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File Remove-WindowsDefender.ps1
Removes every installed Windows-Defender* feature:
Server 2016 Windows-Defender, Windows-Defender-Gui, Windows-Defender-Features
Server 2019/2022 Windows-Defender
The script does not restart the server. It returns 3010 so the restart can be
scheduled through the Tanium action.
Exit codes:
0 Removed with no restart needed, or nothing to remove
3010 Removed, restart required
1 Removal failed
2 Not a server OS, nothing done
#>
# Run as 64-bit so the ServerManager module loads from System32.
if ([Environment]::Is64BitOperatingSystem -and -not [Environment]::Is64BitProcess) {
$ps64 = Join-Path $env:SystemRoot 'Sysnative\WindowsPowerShell\v1.0\powershell.exe'
& $ps64 -NoProfile -NonInteractive -ExecutionPolicy Bypass -File $PSCommandPath
exit $LASTEXITCODE
}
function Write-Log {
param ([string]$Message, [string]$Level = 'INFO')
Write-Output ("{0} [{1}] {2}" -f (Get-Date -Format 'yyyy-MM-dd HH:mm:ss'), $Level, $Message)
}
$os = Get-CimInstance -ClassName Win32_OperatingSystem
Write-Log "Operating system: $($os.Caption)"
if ($os.ProductType -eq 1) {
Write-Log 'Workstation OS detected. Uninstall-WindowsFeature only exists on Windows Server. Nothing done.' 'ERROR'
exit 2
}
try {
$installed = @(Get-WindowsFeature -Name 'Windows-Defender*' -ErrorAction Stop | Where-Object { $_.Installed })
}
catch {
Write-Log "Could not read Windows features: $($_.Exception.Message)" 'ERROR'
exit 1
}
if ($installed.Count -eq 0) {
Write-Log 'No Windows Defender features installed. Nothing to remove.'
exit 0
}
$names = $installed | Select-Object -ExpandProperty Name
Write-Log ("Removing: " + ($names -join ', '))
try {
$result = Uninstall-WindowsFeature -Name $names -ErrorAction Stop
}
catch {
Write-Log "Uninstall-WindowsFeature failed: $($_.Exception.Message)" 'ERROR'
exit 1
}
if (-not $result.Success) {
Write-Log "Removal failed. ExitCode: $($result.ExitCode)" 'ERROR'
exit 1
}
if ("$($result.RestartNeeded)" -eq 'Yes') {
Write-Log 'Removal succeeded. Restart required to finish.'
exit 3010
}
Write-Log 'Removal succeeded. No restart required.'
exit 0
<#
.SYNOPSIS
Deletes leftover Defender platform folders after the Defender feature is removed. Built for a Tanium package.
.DESCRIPTION
Tanium package command:
cmd.exe /d /c powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File Remove-DefenderPlatformLeftovers.ps1
Deletes C:\ProgramData\Microsoft\Windows Defender\Platform. Run it only after
Remove-WindowsDefender.ps1 has completed and the server has restarted.
Safety stop: if the WinDefend service still exists, nothing is deleted.
Exit codes:
0 Folder deleted, or it was not there
1 Delete failed, or the folder is still present
2 WinDefend service still exists, nothing deleted
#>
# Run as 64-bit so paths are not redirected.
if ([Environment]::Is64BitOperatingSystem -and -not [Environment]::Is64BitProcess) {
$ps64 = Join-Path $env:SystemRoot 'Sysnative\WindowsPowerShell\v1.0\powershell.exe'
& $ps64 -NoProfile -NonInteractive -ExecutionPolicy Bypass -File $PSCommandPath
exit $LASTEXITCODE
}
function Write-Log {
param ([string]$Message, [string]$Level = 'INFO')
Write-Output ("{0} [{1}] {2}" -f (Get-Date -Format 'yyyy-MM-dd HH:mm:ss'), $Level, $Message)
}
$platform = Join-Path $env:ProgramData 'Microsoft\Windows Defender\Platform'
Write-Log "Target folder: '$platform'"
# Never delete platform files while Defender is still installed
if (Get-Service -Name 'WinDefend' -ErrorAction SilentlyContinue) {
Write-Log 'WinDefend service still exists. Remove the Defender feature and restart first. Nothing deleted.' 'ERROR'
exit 2
}
if (-not (Test-Path -LiteralPath $platform)) {
Write-Log 'Platform folder not present. Nothing to do.'
exit 0
}
$versions = @(Get-ChildItem -LiteralPath $platform -Directory -Force -ErrorAction SilentlyContinue | Select-Object -ExpandProperty Name)
Write-Log ("Found version folders: " + $(if ($versions) { $versions -join ', ' } else { '(none)' }))
$deleteErrors = @()
Remove-Item -LiteralPath $platform -Recurse -Force -ErrorAction SilentlyContinue -ErrorVariable deleteErrors
if (Test-Path -LiteralPath $platform) {
# The folders are often locked down by ACL. Take ownership for Administrators and retry.
Write-Log "First delete attempt left the folder in place ($($deleteErrors.Count) errors). Taking ownership and retrying." 'WARN'
takeown.exe /F "$platform" /R /A /D Y | Out-Null
icacls.exe "$platform" /grant '*S-1-5-32-544:(OI)(CI)F' /T /C /Q | Out-Null
$deleteErrors = @()
Remove-Item -LiteralPath $platform -Recurse -Force -ErrorAction SilentlyContinue -ErrorVariable deleteErrors
}
if (Test-Path -LiteralPath $platform) {
Write-Log "Folder still present. $($deleteErrors.Count) delete errors." 'ERROR'
$deleteErrors | Select-Object -First 5 | ForEach-Object {
Write-Log " $($_.Exception.Message)" 'ERROR'
}
exit 1
}
Write-Log 'Platform folder deleted.'
exit 0
Verify and close
A machine is done when Tanium shows it in scenario 1, 2, or 10, or the scanner closes the finding after a rescan.
- Rerun question 1 and question 3 against every machine you remediated.
- Confirm each machine shows one of these:
- Product Version at or above
4.18.26040.7and Engine Version at or above1.1.26040.8. C:\Program Files\Windows Defender\MsMpEng.exereturns File does not exist and thePlatformfolder returns Folder does not exist.
- Product Version at or above
- Request a rescan of those machines from the vulnerability scanner.
- Compare the scanner's open findings with your Tanium list. A machine Tanium shows as vulnerable that the scanner does not list is a coverage gap. Check its last scan date and whether its credentialed scan succeeded.