Full Report
One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
Analysis Summary
# Vulnerability: Microsoft Defender for Endpoint (Linux) Service Disruption and Update Failure
## CVE Details
- **CVE ID**: Not explicitly assigned in the report (Vendor bug disclosure)
- **CVSS Score**: N/A (Estimated High impact to Availability/Protection)
- **CWE**: CWE-440 (Expected Behavior Violation) / CWE-755 (Improper Handling of Exceptional Conditions)
## Affected Systems
- **Products**: Microsoft Defender for Endpoint (MDE) for Linux
- **Versions**:
- **Service Disable Bug**: 101.26042.0000 through 101.26042.0009
- **FIPS Update Bug**: 101.26042.x
- **Configurations**:
- All supported Linux distributions (for the service disable bug).
- Red Hat Enterprise Linux (RHEL) 8 and 9 running in **FIPS mode** (for the installation failure).
- Systems with "Defender for Servers" (Plan 1 or 2) and MDE integration enabled (Automatic updates).
## Vulnerability Description
Two primary issues were identified following the June 2026 update cycle:
1. **Service Disablement**: Upon upgrade or reinstallation followed by a system reboot, the Defender service may fail to start, leaving the endpoint without active protection or monitoring.
2. **FIPS Incompatibility**: On hardened RHEL 8/9 systems utilizing FIPS-validated cryptography, the update process fails to complete, preventing the deployment of security patches and leaving the system on an outdated version.
## Exploitation
- **Status**: Not exploited (Functional software regression)
- **Complexity**: N/A (Triggered by system reboot or update process)
- **Attack Vector**: Local (Requires system administrative actions/reboots to manifest)
## Impact
- **Confidentiality**: None (Directly)
- **Integrity**: Low (Security monitoring is bypassed)
- **Availability**: **High** (Security service becomes unavailable, leaving the system defenseless against other threats)
## Remediation
### Patches
Microsoft has released the following builds to address these issues:
- **For the Service Disable bug**: Update to version **101.26042.0011** or later.
- **For the FIPS Installation bug**: Update to version **101.26052.0011** or later.
### Workarounds
- **Manual Service Restart**: Administrators should manually verify the status of the `mdatp` service after reboots on affected versions and start it if it is found in a disabled state.
- **Rollback**: Roll back to a stable version prior to 101.26042.0000 if immediate patching to the .0011+ builds is not possible.
## Detection
- **Indicators of Compromise**: No indicators of malicious activity, but "Service Disabled" alerts may appear in the Microsoft Defender portal.
- **Detection Methods**:
- Run `mdatp health` on Linux endpoints to verify if the "real_time_protection_enabled" status is true.
- Monitor system logs for service start failures related to `microsoft-defender-endpoint`.
- Audit RHEL FIPS systems to ensure the agent version has successfully advanced beyond 101.26042.x.
## References
- Microsoft Release Notes: hxxps[://]learn[.]microsoft[.]com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#linux--june-2026%E2%80%94101260420009
- Microsoft Advisory: hxxps[://]mc[.]merill[.]net/message/MC1438566