Vulnerabilità · 159 giorni fa
Defender’s file rewrite turns patched PCs into SYSTEM targets Microsoft Defender’s cloud-tag handling creates a local privilege escalation path that can still hand an attacker SYSTEM on fully patched Windows systems. The standard response of “we patched Patch Tuesday” misses the point here: if Defender is enabled, the product itself can be used to rewrite a file into a privileged system location.
Chaotic Eclipse published a proof of concept for CVE-2026-33825 , and independent confirmation says it works on Windows 10, Windows 11, and Windows Server 2019 and later with the latest April Patch Tuesday updates. The flaw is tied to Defender’s Cloud Files behavior, which lets a malicious file rewrite land in a system path and overwrite a protected executable.
The risk persists until Microsoft ships a fix or mitigation. This is a local foothold-to-SYSTEM path on endpoints that are already current, so patch status alone does not rule out compromise.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Patch Microsoft: Release Notes.
Data di correzione federale CISA 6 mag
Cronologia Fonti 7 fonti che coprono questa storia
BleepingComputer 23 apr
CISA orders feds to patch BlueHammer flaw exploited as zero-day
federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.
SecurityWeek 23 apr
Recent Microsoft Defender Vulnerability Exploited as Zero-Day
The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges.
Dark Reading 21 apr
Exploits Turn Windows Defender Into Attacker Tool
Three proof-of-concept exploits are being used in active attacks against Microsoft's built-in security platform; two are unpatched.
The Hacker News 17 apr
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Three Defender zero-days exploited since April 10, 2026, enabling privilege escalation and DoS, forcing isolation of affected systems.
TechCrunch Security 17 apr
Hackers are abusing unpatched Windows security flaws to hack into organizations | TechCrunch
A security researcher published details of three security vulnerabilities in Windows Defender, and the code used to exploit them.
Help Net Security 17 apr
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild - Help Net Security
The researcher who earlier this month published a PoC exploit for a zero-day LPE vulnerability in Microsoft Defender is back with two more.
CSO Online 17 apr
Another Microsoft Defender privilege escalation bug emerges days after patch
New PoC shows how Microsoft Defender can be tricked into rewriting malicious files into protected locations, enabling SYSTEM-level privilege escalation on fully patched Windows systems.
BleepingComputer 16 apr
New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges
A researcher known as "Chaotic Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity researchers.
Entità CVE-2026-33825 Chaotic Eclipse Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-04-18
Editions Storie correlate
Vulnerabilità · 159 giorni fa
Defender’s file rewrite turns patched PCs into SYSTEM targets Microsoft Defender’s cloud-tag handling creates a local privilege escalation path that can still hand an attacker SYSTEM on fully patched Windows systems. The standard response of “we patched Patch Tuesday” misses the point here: if Defender is enabled, the product itself can be used to rewrite a file into a privileged system location.
Chaotic Eclipse published a proof of concept for CVE-2026-33825 , and independent confirmation says it works on Windows 10, Windows 11, and Windows Server 2019 and later with the latest April Patch Tuesday updates. The flaw is tied to Defender’s Cloud Files behavior, which lets a malicious file rewrite land in a system path and overwrite a protected executable.
The risk persists until Microsoft ships a fix or mitigation. This is a local foothold-to-SYSTEM path on endpoints that are already current, so patch status alone does not rule out compromise.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Patch Microsoft: Release Notes.
Data di correzione federale CISA 6 mag
Cronologia Fonti 7 fonti che coprono questa storia
BleepingComputer 23 apr
CISA orders feds to patch BlueHammer flaw exploited as zero-day
federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.
SecurityWeek 23 apr
Recent Microsoft Defender Vulnerability Exploited as Zero-Day
The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges.
Dark Reading 21 apr
Exploits Turn Windows Defender Into Attacker Tool
Three proof-of-concept exploits are being used in active attacks against Microsoft's built-in security platform; two are unpatched.
The Hacker News 17 apr
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Three Defender zero-days exploited since April 10, 2026, enabling privilege escalation and DoS, forcing isolation of affected systems.
TechCrunch Security 17 apr
Hackers are abusing unpatched Windows security flaws to hack into organizations | TechCrunch
A security researcher published details of three security vulnerabilities in Windows Defender, and the code used to exploit them.
Help Net Security 17 apr
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild - Help Net Security
The researcher who earlier this month published a PoC exploit for a zero-day LPE vulnerability in Microsoft Defender is back with two more.
CSO Online 17 apr
Another Microsoft Defender privilege escalation bug emerges days after patch
New PoC shows how Microsoft Defender can be tricked into rewriting malicious files into protected locations, enabling SYSTEM-level privilege escalation on fully patched Windows systems.
BleepingComputer 16 apr
New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges
A researcher known as "Chaotic Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity researchers.
Entità CVE-2026-33825 Chaotic Eclipse Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-04-18
Editions Storie correlate