Vulnerabilities · 145 days ago
Defender’s file rewrite turns patched PCs into SYSTEM targets Microsoft Defender’s cloud-tag handling creates a local privilege escalation path that can still hand an attacker SYSTEM on fully patched Windows systems. The standard response of “we patched Patch Tuesday” misses the point here: if Defender is enabled, the product itself can be used to rewrite a file into a privileged system location.
Chaotic Eclipse published a proof of concept for CVE-2026-33825 , and independent confirmation says it works on Windows 10, Windows 11, and Windows Server 2019 and later with the latest April Patch Tuesday updates. The flaw is tied to Defender’s Cloud Files behavior, which lets a malicious file rewrite land in a system path and overwrite a protected executable.
The risk persists until Microsoft ships a fix or mitigation. This is a local foothold-to-SYSTEM path on endpoints that are already current, so patch status alone does not rule out compromise.
NVD KEV
Known exploited · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Microsoft patch: Release Notes.
CISA federal remediation date May 6
Timeline Sources 7 sources covering this story
BleepingComputer Apr 23
CISA orders feds to patch BlueHammer flaw exploited as zero-day
federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.
SecurityWeek Apr 23
Recent Microsoft Defender Vulnerability Exploited as Zero-Day
The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges.
Dark Reading Apr 21
Exploits Turn Windows Defender Into Attacker Tool
Three proof-of-concept exploits are being used in active attacks against Microsoft's built-in security platform; two are unpatched.
The Hacker News Apr 17
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Three Defender zero-days exploited since April 10, 2026, enabling privilege escalation and DoS, forcing isolation of affected systems.
TechCrunch Security Apr 17
Hackers are abusing unpatched Windows security flaws to hack into organizations | TechCrunch
A security researcher published details of three security vulnerabilities in Windows Defender, and the code used to exploit them.
Help Net Security Apr 17
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild - Help Net Security
The researcher who earlier this month published a PoC exploit for a zero-day LPE vulnerability in Microsoft Defender is back with two more.
CSO Online Apr 17
Another Microsoft Defender privilege escalation bug emerges days after patch
New PoC shows how Microsoft Defender can be tricked into rewriting malicious files into protected locations, enabling SYSTEM-level privilege escalation on fully patched Windows systems.
BleepingComputer Apr 16
New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges
A researcher known as "Chaotic Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity researchers.
Entities CVE-2026-33825 Chaotic Eclipse Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-04-18
Editions Related stories
Vulnerabilities · 145 days ago
Defender’s file rewrite turns patched PCs into SYSTEM targets Microsoft Defender’s cloud-tag handling creates a local privilege escalation path that can still hand an attacker SYSTEM on fully patched Windows systems. The standard response of “we patched Patch Tuesday” misses the point here: if Defender is enabled, the product itself can be used to rewrite a file into a privileged system location.
Chaotic Eclipse published a proof of concept for CVE-2026-33825 , and independent confirmation says it works on Windows 10, Windows 11, and Windows Server 2019 and later with the latest April Patch Tuesday updates. The flaw is tied to Defender’s Cloud Files behavior, which lets a malicious file rewrite land in a system path and overwrite a protected executable.
The risk persists until Microsoft ships a fix or mitigation. This is a local foothold-to-SYSTEM path on endpoints that are already current, so patch status alone does not rule out compromise.
NVD KEV
Known exploited · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Microsoft patch: Release Notes.
CISA federal remediation date May 6
Timeline Sources 7 sources covering this story
BleepingComputer Apr 23
CISA orders feds to patch BlueHammer flaw exploited as zero-day
federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.
SecurityWeek Apr 23
Recent Microsoft Defender Vulnerability Exploited as Zero-Day
The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges.
Dark Reading Apr 21
Exploits Turn Windows Defender Into Attacker Tool
Three proof-of-concept exploits are being used in active attacks against Microsoft's built-in security platform; two are unpatched.
The Hacker News Apr 17
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Three Defender zero-days exploited since April 10, 2026, enabling privilege escalation and DoS, forcing isolation of affected systems.
TechCrunch Security Apr 17
Hackers are abusing unpatched Windows security flaws to hack into organizations | TechCrunch
A security researcher published details of three security vulnerabilities in Windows Defender, and the code used to exploit them.
Help Net Security Apr 17
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild - Help Net Security
The researcher who earlier this month published a PoC exploit for a zero-day LPE vulnerability in Microsoft Defender is back with two more.
CSO Online Apr 17
Another Microsoft Defender privilege escalation bug emerges days after patch
New PoC shows how Microsoft Defender can be tricked into rewriting malicious files into protected locations, enabling SYSTEM-level privilege escalation on fully patched Windows systems.
BleepingComputer Apr 16
New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges
A researcher known as "Chaotic Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity researchers.
Entities CVE-2026-33825 Chaotic Eclipse Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-04-18
Editions Related stories