Public Windows Privilege Escalation Exploit Raises Zero-Day Risk

The public release of a working local Windows privilege-escalation exploit called BlueHammer breaks the assumption that privately reported flaws remain unexploitable until patched. A disgruntled researcher published the exploit code on GitHub after a dispute with Microsoft’s Security Response Center, while the vulnerability remains unpatched and thus a true zero-day. This exploit allows any local user or compromised account to escalate privileges to SYSTEM or elevated admin, expanding the attack surface on every Windows host where code execution is possible. Standard patch-waiting strategies are insufficient because the exploit is now publicly available and requires only local code execution, not network access. This increases immediate operational risk for environments with exposed or easily compromised Windows endpoints such as RDP hosts, shared workstations, and developer machines.

Part of the PlainSec briefing for 2026-04-10

Editions

Sources