CVE-2026-33825Active Exploitation(microsoft / defender_antimalware_platform)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 26 mentions and remains active

Immediate actions

  • Patch microsoft defender_antimalware_platform systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-06. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-1220

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • defender_antimalware_platform

Threat summary

  • Active exploitation appears in 114 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 223 mentions across 54 observed days

What's happening

  • Active exploitation reported across 114 signals
  • Exploit tool or code specified in 27 signals
  • PoC mentioned or linked in 47 signals
  • Patch or workaround mentioned in 111 signals
  • Technical details provided in 133 signals
  • General: 32 classified signals
  • Peaked 50d ago at 26 mentions (2026-04-17); latest day: 1
  • 223 total mentions across 54 days

Affected systems

Vendors
Products
defender_antimalware_platform

Deep dive

Activity timeline223 mentions / 54d
07132026Mentions · 2026-04-14: 4Mentions · 2026-04-15: 23Mentions · 2026-04-16: 23Mentions · 2026-04-17: 26Mentions · 2026-04-18: 6Mentions · 2026-04-19: 5Mentions · 2026-04-20: 8Mentions · 2026-04-21: 4Mentions · 2026-04-22: 7Mentions · 2026-04-23: 18Mentions · 2026-04-24: 5Mentions · 2026-04-25: 6Mentions · 2026-04-26: 6Mentions · 2026-04-27: 5Mentions · 2026-04-28: 2Mentions · 2026-05-01: 2Mentions · 2026-05-03: 2Mentions · 2026-05-04: 2Mentions · 2026-05-15: 6Mentions · 2026-05-21: 5Mentions · 2026-05-22: 1Mentions · 2026-05-26: 1Mentions · 2026-05-28: 1Mentions · 2026-05-30: 1Mentions · 2026-06-02: 2Mentions · 2026-06-04: 1Mentions · 2026-06-07: 1Mentions · 2026-06-12: 2Mentions · 2026-06-13: 2Mentions · 2026-06-14: 1Mentions · 2026-06-15: 1Mentions · 2026-06-16: 3Mentions · 2026-06-17: 2Mentions · 2026-06-22: 1Mentions · 2026-06-23: 2Mentions · 2026-06-30: 5Mentions · 2026-07-01: 10Mentions · 2026-07-02: 3Mentions · 2026-07-03: 2Mentions · 2026-07-04: 1Mentions · 2026-07-05: 1Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Mentions · 2026-07-09: 1Mentions · 2026-07-10: 1Mentions · 2026-07-14: 1Mentions · 2026-07-15: 1Mentions · 2026-07-16: 1Mentions · 2026-07-17: 1Mentions · 2026-07-19: 2Mentions · 2026-07-22: 1Mentions · 2026-08-04: 1Mentions · 2026-08-11: 1Mentions · 2026-08-16: 1PoC Mentioned / Linked · 2026-04-15: 5PoC Mentioned / Linked · 2026-04-16: 9PoC Mentioned / Linked · 2026-04-17: 6PoC Mentioned / Linked · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-20: 3PoC Mentioned / Linked · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-23: 5PoC Mentioned / Linked · 2026-04-24: 1PoC Mentioned / Linked · 2026-04-25: 3PoC Mentioned / Linked · 2026-04-26: 2PoC Mentioned / Linked · 2026-04-27: 2PoC Mentioned / Linked · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-21: 2PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-06-17: 1PoC Mentioned / Linked · 2026-07-01: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-10: 1Exploit Tool / Code · 2026-04-15: 2Exploit Tool / Code · 2026-04-16: 5Exploit Tool / Code · 2026-04-17: 4Exploit Tool / Code · 2026-04-19: 1Exploit Tool / Code · 2026-04-20: 1Exploit Tool / Code · 2026-04-23: 3Exploit Tool / Code · 2026-04-24: 1Exploit Tool / Code · 2026-04-25: 2Exploit Tool / Code · 2026-04-26: 1Exploit Tool / Code · 2026-04-27: 1Exploit Tool / Code · 2026-05-03: 1Exploit Tool / Code · 2026-05-15: 1Exploit Tool / Code · 2026-05-21: 2Exploit Tool / Code · 2026-05-30: 1Exploit Tool / Code · 2026-07-01: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-15: 9Active Exploitation · 2026-04-16: 7Active Exploitation · 2026-04-17: 8Active Exploitation · 2026-04-18: 2Active Exploitation · 2026-04-19: 5Active Exploitation · 2026-04-20: 5Active Exploitation · 2026-04-21: 3Active Exploitation · 2026-04-22: 4Active Exploitation · 2026-04-23: 14Active Exploitation · 2026-04-24: 4Active Exploitation · 2026-04-25: 4Active Exploitation · 2026-04-26: 3Active Exploitation · 2026-04-27: 4Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-05-15: 2Active Exploitation · 2026-05-21: 4Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-26: 1Active Exploitation · 2026-05-30: 1Active Exploitation · 2026-06-16: 1Active Exploitation · 2026-06-30: 5Active Exploitation · 2026-07-01: 8Active Exploitation · 2026-07-02: 3Active Exploitation · 2026-07-03: 2Active Exploitation · 2026-07-04: 1Active Exploitation · 2026-07-05: 1Active Exploitation · 2026-07-06: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-14: 1Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-17: 1Active Exploitation · 2026-07-19: 2Active Exploitation · 2026-08-11: 1Active Exploitation · 2026-08-16: 1Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-04-15: 8Patch / Workaround · 2026-04-16: 17Patch / Workaround · 2026-04-17: 13Patch / Workaround · 2026-04-18: 2Patch / Workaround · 2026-04-19: 4Patch / Workaround · 2026-04-20: 5Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-22: 2Patch / Workaround · 2026-04-23: 13Patch / Workaround · 2026-04-24: 4Patch / Workaround · 2026-04-25: 3Patch / Workaround · 2026-04-26: 2Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-05-01: 2Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-22: 1Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-06-02: 1Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-14: 1Patch / Workaround · 2026-06-16: 2Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-30: 3Patch / Workaround · 2026-07-01: 4Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 2Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-19: 2Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-15: 12Technical Details · 2026-04-16: 13Technical Details · 2026-04-17: 19Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 4Technical Details · 2026-04-20: 3Technical Details · 2026-04-21: 3Technical Details · 2026-04-22: 6Technical Details · 2026-04-23: 13Technical Details · 2026-04-24: 4Technical Details · 2026-04-25: 5Technical Details · 2026-04-26: 5Technical Details · 2026-04-27: 3Technical Details · 2026-04-28: 2Technical Details · 2026-05-01: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-15: 3Technical Details · 2026-05-21: 3Technical Details · 2026-05-22: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-30: 3Technical Details · 2026-07-01: 6Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-15: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-22: 1Technical Details · 2026-08-11: 104-1404-1904-2405-0105-2206-0406-1506-3007-0507-1407-2208-16
Signal classification6 categories
Active Exploitation
10044.8%
Patch
4319.3%
General
3214.3%
Disclosure
2712.1%
PoC
188.1%
Exploit
31.3%
Referenced assets125 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-144
Active Exploitation1Disclosure1Patch2
2026-04-1523
Active Exploitation7Disclosure5General6Patch3PoC2
2026-04-1623
Active Exploitation3Disclosure2General1Patch10PoC7
2026-04-1726
Active Exploitation8Disclosure2Exploit1General5Patch6PoC4
2026-04-186
Active Exploitation2General3PoC1
2026-04-195
Active Exploitation4Patch1
2026-04-208
Active Exploitation4Disclosure1Patch2PoC1
2026-04-214
Active Exploitation3Disclosure1
2026-04-227
Active Exploitation4Disclosure2Patch1
2026-04-2318
Active Exploitation11Disclosure1General1Patch4PoC1
2026-04-245
Active Exploitation3General1Patch1
2026-04-256
Active Exploitation4General2
2026-04-266
Active Exploitation3Disclosure2Patch1
2026-04-275
Active Exploitation3Disclosure1Patch1
2026-04-282
Disclosure2
2026-05-012
Active Exploitation1Patch1
2026-05-032
Exploit1General1
2026-05-042
General1Patch1
2026-05-156
Active Exploitation2Disclosure3General1
2026-05-215
Active Exploitation4Exploit1
2026-05-221
Active Exploitation1
2026-05-261
Active Exploitation1
2026-05-281
General1
2026-05-301
Active Exploitation1
2026-06-022
General1Patch1
2026-06-041
General1
2026-06-071
Patch1
2026-06-122
Disclosure1Patch1
2026-06-132
General2
2026-06-141
Patch1
2026-06-151
Disclosure1
2026-06-163
Active Exploitation1Patch1PoC1
2026-06-172
General1PoC1
2026-06-221
General1
2026-06-232
General1Patch1
2026-06-305
Active Exploitation5
2026-07-0110
Active Exploitation8Patch2
2026-07-023
Active Exploitation3
2026-07-032
Active Exploitation2
2026-07-041
Active Exploitation1
2026-07-051
Active Exploitation1
2026-07-061
Active Exploitation1
2026-07-071
Disclosure1
2026-07-091
Disclosure1
2026-07-101
Active Exploitation1
2026-07-141
Active Exploitation1
2026-07-151
General1
2026-07-161
Active Exploitation1
2026-07-171
Active Exploitation1
2026-07-192
Active Exploitation2
2026-07-221
General1
2026-08-041
Patch1
2026-08-111
Active Exploitation1
2026-08-161
Active Exploitation1
Full discourse20 posts
  • Pirat_Nation 🔴@Pirat_Nation
    Active Exploitation

    Microsoft released a new patch to fix 167 security vulnerabilities across Windows and related software. Most importantly, two of them are zero-day vulnerabilities: >CVE-2026-32201: A SharePoint Server spoofing flaw already being actively exploited in the wild. >CVE-2026-33825: A flaw in Microsoft Defender that allows local attackers to gain SYSTEM-level access. They also fixed remote code execution issues in Microsoft Office. Guys If you use Windows, install these updates immediately especially if you run SharePoint or handle Office documents At this point just install Linux

    Post summary

    Microsoft has released patches for 167 CVEs, including two zero-days—CVE-2026-32201, actively exploited in the wild, and CVE-2026-33825 that grants SYSTEM-level access. Users, especially those running SharePoint or Office, should install the updates immediately.

    73157131.9K374130.8K
    332.5K followersView on X
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    🚨 Three Windows zero-days released by Nightmare-Eclipse are being used in the wild by threat actors. BlueHammer (CVE-2026-33825): LPE, Abuses Windows Defender’s signature-update pipeline and VSS to breach protected registry hives, dump SAM hashes/identities, and escalate privileges. RedSun: LPE to SYSTEM abusing Defender's own cloud remediation to overwrite System32 binaries. UnDefend: Unprivileged DoS that starves the AV of updates while spoofing healthy EDR telemetry.

    Post summary

    Three zero‑day CVEs in Windows Defender are actively exploited in the wild, enabling privilege escalation, SAM hash extraction, binary overwrite, and denial‑of‑service attacks.

    16141131.2K45081.5K
    182.0K followersView on X
  • impulsive@weezerOSINT
    General

    heres where it gets crazy. this isnt some random bug. the same person dropped 3 windows 0days in 13 days BlueHammer (april 2) - defender LPE. got CVE-2026-33825. patched UnDefend (april 12) - blocks all defender updates permanently RedSun (april 15) - this one. still unpatched they claim MSRC dismissed their reports and "ruined their life." direct quote from their blog: "I was not bluffing Microsoft, and I'm doing it again" they are threatening to drop an RCE next

    Post summary

    The post enumerates three Windows zero‑days, notes a patch for one, highlights a threat of a forthcoming RCE, but provides no PoC or evidence of active exploitation.

    14413686117179.3K
    10.5K followersView on X
  • Chaotic Eclipse@ChaoticEclipse0
    Disclosure

    In response to CVE-2026-33825 (BlueHammer patch), The RedSun, a new unpatched windows defender EoP vulnerability has been publicly disclosed and can be found here - https://deadeclipse666.blogspot.com/2026/04/public-disclosure-response-for-cve-2026.html

    Post summary

    The post announces a new Windows Defender EoP vulnerability (RedSun) and points to a blog post, while also noting a BlueHammer patch for a separate CVE; it provides no PoC, exploit, or evidence of active attacks.

    1188739315267.8K
    13.0K followersView on X
  • 辻 伸弘 (nobuhiro tsuji)@ntsuji
    PoC

    Microsoft Defender にゼロデイの脆弱性(CVE-2026-33825)。当該脆弱性は権限昇格が可能となるもので低権限のユーザがSYSTEM権限を奪取可能となります。現在、悪用は検出されていないもののPoCが公開されておりますので、悪用が確認されるのも時間の問題かもしれませんね。 リモートから即座に悪用可能な脆弱性ではないものの内部侵入後の影響が大きいため対処しおくことが望ましいです。こちらの脆弱性は今月のパッチチューズデイで修正済み。 なお、脆弱性スキャナなどでのチェックでは、Defenderが無効でも検知上は脆弱扱いになる場合がありますが、これはDefenderのバイナリのチェックによるもので実際には無効状態なら悪用不可とこと。 https://cybersecuritynews.com/microsoft-defender-0-day-vulnerability/

    Post summary

    Microsoft disclosed a zero‑day privilege‑escalation flaw in Defender (CVE‑2026‑33825), a PoC has been posted, no active exploitation yet, and a patch was released on Patch Tuesday.

    26411916420.9K
    28.6K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚡ Researchers confirm exploitation of three Microsoft Defender flaws—one patched (CVE-2026-33825) , two unpatched. Attackers escalate privileges and can block Defender updates. 🔗 Learn how these flaws are used in attacks → https://thehackernews.com/2026/04/three-microsoft-defender-zero-days.html

    Post summary

    Researchers have confirmed that three Microsoft Defender flaws—two of which remain unpatched—are actively exploited, allowing privilege escalation and blocking updates, while one vulnerability has already been patched.

    75741442814.5K
    1.7M followersView on X
  • ɐʞsǝs@akses_0x00
    Patch

    in case anyone is wondering it looks like RedSun still works if you are patched for CVE-2026-33825 so any community notes out there suggestion thats the case, maybe ignore those https://t.co/fqlrhDHmcj

    Post summary

    The tweet confirms that applying the patch for CVE-2026‑33825 allows RedSun to function normally, with no indication of PoC or active exploitation.

    291973611.8K
    507 followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    BlueHammer - Public disclosure, a response for CVE-2026-33825 patch https://deadeclipse666.blogspot.com/2026/04/public-disclosure-response-for-cve-2026.html PoC https://github.com/Nightmare-Eclipse/RedSun

    Post summary

    BlueHammer publicly discloses CVE‑2026‑33825, providing both a patch and a proof‑of‑concept repository for the vulnerability.

    011086314.1K
    157.5K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    مايكروسفت تهدد برفع قضايا على الباحث الامني Nightmare Eclipse بعد مابهدلهم ونشر 6 ثغرات 0day (RedSun) CVE-2026-41091 (UnDefend) CVE-2026-45498 (BlueHammer) CVE-2026-33825 (YellowKey) CVE-2026-45585 (GreenPlasma) (MiniPlasma) مو من صالحهم يعادون مجتمع الباحثين بهالطريقه https://t.co/bFoufGGRYW

    Post summary

    The tweet alleges Microsoft has threatened legal action against a researcher for publishing six zero‑day CVEs, but it provides no technical details, exploit code, or evidence of active exploitation.

    581453522.4K
    50.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Microsoft Defender insufficient granularity of access control vulnerability CVE-2026-33825 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. https://t.co/DW9iZRYJPt

    Post summary

    The tweet announces CVE-2026-33825’s inclusion in DHS’s Known Exploited Vulnerabilities Catalog, indicating it is actively exploited, but provides no PoC, patch, or detailed technical information.

    22114567.3K
    299.5K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Windows Defenderのゼロデイ脆弱性"RedSun"が公表された。"BlueHammer" (CVE-2026-33825)の報告者が、MSの修正内容に不満を持ち追加で公表したもの。BlueHammer同様SYSTEM奪取可能な権限昇格。 https://securityonline.info/redsun-windows-defender-zero-day-elevation-of-privilege-poc/

    Post summary

    RedSun is a newly disclosed Windows Defender privilege‑escalation zero‑day that is publicly accompanied by a PoC, with no indication of active exploitation or patches yet.

    48431157.1K
    7.6K followersView on X
  • Cyber_Racheal@CyberRacheal
    Patch

    The security landscape just shifted because of a critical vulnerability in Microsoft Defender known as BlueHammer. Tracked as CVE-2026-33825, this exploit allows a local attacker, or a malicious app already on your system, to bypass standard security checks and gain SYSTEM privileges, the highest level of administrative access. This is particularly dangerous because the very tool meant to protect your PC is used as the gateway for the attack. While Microsoft released an emergency patch on April 14, 2026, many systems remain vulnerable if they haven't yet applied the latest antimalware platform updates. If a machine is compromised through this vector, ransomware gangs can gain total control, allowing them to disable security logs and encrypt the entire hard drive. Beyond just locking your files, this level of access enables data exfiltration,where hackers steal sensitive information like saved browser passwords, session cookies, and Discord tokens to hijack your online identity. Even on a fully patched version of Windows 11, the threat persists if the specific Defender engine update (v4.18.26030.3011 or later) has not been installed. To stay safe, you should immediately manually check for protection updates within the Windows Security app.

    Post summary

    The post announces a critical CVE in Microsoft Defender, highlights the emergency patch published on April 14 2026, and urges users to apply the Defender engine update to mitigate a privilege‑escalation vulnerability.

    27216103.8K
    26.7K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    وكالة CISA أكدت أن ثغرة في BlueHammer في Microsoft Defender ورقمها CVE-2026-33825 أصبحت تُستغل من عصابات فدية. الثغرة من نوع تصعيد الصلاحيات مايكروسوفت أصلحتها في تحديثات أبريل 2026، وCISA أضافتها لقائمة KEV من أبريل، والآن صنفتها كـ “Known” في حملات الفدية. https://t.co/qstpcr2g3w

    Post summary

    CISA confirms that CVE-2026-33825 in BlueHammer (Microsoft Defender) is being actively exploited by ransomware gangs; Microsoft released a patch in the April 2026 update.

    02015123.1K
    50.1K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    There’s also BlueHammer, a Defender exploit disclosed publicly. It exposed registry hives, enabled SYSTEM access, and restored changes to avoid detection. Microsoft has now patched it under CVE-2026-33825.

    Post summary

    Microsoft has released a patch for CVE-2026-33825, after the BlueHammer Defender exploit was publicly disclosed and detailed its ability to gain SYSTEM access and manipulate registry hives.

    1501268.0K
    1.7M followersView on X
  • /r/netsec@_r_netsec
    General

    CVE-2026-33825 deep-dive: The researcher commented out the full credential dump. Here's what that means. https://nefariousplan.com/posts/bluhammer/

    Post summary

    The text references a deep‑dive article on CVE‑2026‑33825 but does not provide concrete PoC, exploit, patch, or technical details.

    0201231.3K
    33.3K followersView on X
  • Raunak Yadush@raunak_yadush
    Disclosure

    heres where it gets crazy. this isnt some random bug. the same person dropped 3 windows 0days in 13 days BlueHammer (april 2) - defender LPE. got CVE-2026-33825. patched UnDefend (april 12) - blocks all defender updates permanently RedSun (april 15) - this one. still unpatched they claim MSRC dismissed their reports and "ruined their life." direct quote from their blog: "I was not bluffing Microsoft, and I'm doing it again" they are threatening to drop an RCE next

    Post summary

    The post announces three Windows zero-day CVEs, notes patch status for one, and highlights the threat of a future RCE, but does not provide PoC or exploit details.

    2301022.4K
    23.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    CISA adds BlueHammer (CVE-2026-33825) to the KEV catalog. This Microsoft Defender LPE exploit uses TOCTOU to hijack SAM databases. Patch by May 6, 2026. #BlueHammer #MicrosoftDefender #CyberSecurity #InfoSec #LPE #CISA #PatchNow #ZeroDay https://securityonline.info/bluehammer-exploit-cve-2026-33825-microsoft-defender-lpe/ https://t.co/6wV9y2riBi

    Post summary

    CISA has added CVE‑2026‑33825 (BlueHammer) to its KEV catalog, describing a Microsoft Defender local privilege escalation that hijacks SAM databases via a TOCTOU flaw. A patch is available, due by May 6, 2026.

    15061441
    12.5K followersView on X
  • yousukezan@yousukezan
    PoC

    Microsoft Defenderのゼロデイ脆弱性「RoguePlanet」が公開され、SYSTEM権限の取得が可能になることが明らかになった。Microsoftは現在修正プログラムを開発中で、CVE-2026-50656として追跡している。 Microsoftはこの問題を権限昇格の脆弱性と説明しており、CVSSスコアは7.8。Microsoft Malware Protection Engineに存在し、同社は「高品質なセキュリティ更新プログラムの提供に向けて作業している」としている。 RoguePlanetは研究者のChaotic Eclipse(Nightmare-Eclipse)が先週公開した。公開されたPoCは競合状態(Race Condition)を悪用するもので、成功するとSYSTEM権限のシェルを取得できる。研究者によると成功率は環境によって異なるが、一部環境では100%の成功率を確認したという。 さらに研究者は、リアルタイム保護の有効・無効に関係なくPoCが動作すると説明しており、Defenderのパッシブモードでも影響する可能性があるとしている。 Microsoftは公開当初から脆弱性の有効性と影響範囲を調査していた。Chaotic Eclipseが公開したDefender関連の脆弱性は今回で4件目となり、過去のBlueHammer(CVE-2026-33825)、UnDefend(CVE-2026-45498)、RedSun(CVE-2026-41091)はすでに修正されている。 https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html

    Post summary

    A proof of concept for the CVE-2026-50656 privilege‑escalation flaw in Microsoft Defender was released by Chaotic Eclipse, and Microsoft is developing a patch.

    020821.4K
    14.8K followersView on X
  • 𝔇𝔢𝔯 ℭ𝔥𝔲𝔡@der_chuddie
    Patch

    @Pirat_Nation Microsoft released a new patch to fix 167 street shitters code blocks. >CVE-2026-32201: shitting on Sharepoint >CVE-2026-33825: shitting on Defender Run flush.exe with admin rights to install patch

    Post summary

    The tweet notes that Microsoft issued a patch for two CVEs and advises running a cleanup tool, but offers no technical detail or evidence of exploitation.

    0001022.7K
    126 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    だいぶお怒りの様子... Chaotic Eclipse: Public disclosure, a response for CVE-2026-33825 patch https://deadeclipse666.blogspot.com/2026/04/public-disclosure-response-for-cve-2026.html

    Post summary

    The post announces or references a patch response for CVE-2026-33825, but does not provide exploit details or evidence of active exploitation.

    121521.7K
    6.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdefender_antimalware_platform---

Explore more