New Microsoft Defender Privilege Escalation Vulnerabilities and PoCs Emerge
8 Articles
8 Articles
New Microsoft Defender Privilege Escalation Vulnerabilities and PoCs Emerge
Archyde On April 17, 2026, the BlueHammer leaker published a new proof-of-concept exploit targeting a critical privilege escalation flaw in Microsoft Defender for Endpoint, reigniting tensions after a public dispute with ... Read More The post New Microsoft Defender Privilege Escalation Vulnerabilities and PoCs Emerge appeared first on Archyde.
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems. The activity involves the exploitation of three vulnerabilities that are codenamed BlueHammer (requires GitHub sign-in), RedSun, and UnDefend, all of which were released as zero-days by a researcher known as Chaotic Eclipse (
A few days after BlueHammer, researcher Chaotic Eclipse puts a piece in the machine with RedSun, a zero-day flaw affecting Microsoft Defender, able to open SYSTEM rights on Windows PCs yet up-to-date.
Another Microsoft Defender privilege escalation bug emerges days after patch
Days after Microsoft patched a high-severity issue affecting its Windows Defender antivirus tool through April’s Patch Tuesday, researchers warn of another vulnerability that could enable SYSTEM privileges through local escalation. In a newly disclosed proof-of-concept (PoC) exploit, dubbed “RedSun,” GitHub user going by the name “Nightmare Eclipse” demonstrated how Microsoft Defender’s handling of certain cloud-tagged files can be abused to ove…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium



