CVE-2026-33825
Known exploited · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Microsoft patch: Release Notes.
CISA federal remediation date May 6
Vulnerabilities & Exploits · Zero-Day Exploit
Microsoft Defender’s cloud-tag handling creates a local privilege escalation path that can still hand an attacker SYSTEM on fully patched Windows systems. The standard response of “we patched Patch Tuesday” misses the point here: if Defender is enabled, the product itself can be used to rewrite a file into a privileged system location.
Chaotic Eclipse published a proof of concept for CVE-2026-33825, and independent confirmation says it works on Windows 10, Windows 11, and Windows Server 2019 and later with the latest April Patch Tuesday updates. The flaw is tied to Defender’s Cloud Files behavior, which lets a malicious file rewrite land in a system path and overwrite a protected executable.
The risk persists until Microsoft ships a fix or mitigation. This is a local foothold-to-SYSTEM path on endpoints that are already current, so patch status alone does not rule out compromise.
7 sources · Apr 23
Known exploited · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Microsoft patch: Release Notes.
CISA federal remediation date May 6
BleepingComputer
CISA orders feds to patch BlueHammer flaw exploited as zero-day
federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.
originalSecurityWeek
Recent Microsoft Defender Vulnerability Exploited as Zero-Day
The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges.
originalDark Reading
Exploits Turn Windows Defender Into Attacker Tool
Three proof-of-concept exploits are being used in active attacks against Microsoft's built-in security platform; two are unpatched.
originalPart of the PlainSec briefing for 2026-04-18
Every edition of this story: Defender’s file rewrite turns patched PCs into SYSTEM targets