Defender’s file rewrite turns patched PCs into SYSTEM targets

Microsoft Defender’s cloud-tag handling creates a local privilege escalation path that can still hand an attacker SYSTEM on fully patched Windows systems. The standard response of “we patched Patch Tuesday” misses the point here: if Defender is enabled, the product itself can be used to rewrite a file into a privileged system location. Chaotic Eclipse published a proof of concept for CVE-2026-33825, and independent confirmation says it works on Windows 10, Windows 11, and Windows Server 2019 and later with the latest April Patch Tuesday updates. The flaw is tied to Defender’s Cloud Files behavior, which lets a malicious file rewrite land in a system path and overwrite a protected executable. The risk persists until Microsoft ships a fix or mitigation. This is a local foothold-to-SYSTEM path on endpoints that are already current, so patch status alone does not rule out compromise.

Part of the PlainSec briefing for 2026-04-18

Sources