Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-33825 | Local Privilege Escalation in Microsoft Defender Antimalware Platform CVE-2026-33825 is an insufficient granularity of access control flaw (CWE-1220) in Microsoft Defender Antimalware Platform that allows an authorized attacker to elevate privileges locally. It is triggered by an attacker who already holds a low-privileged foothold on a machine running Defender, with no user interaction required. Successful exploitation has high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8), granting elevated local rights that facilitate defense evasion, persistence, or ransomware activity. Any organization running Microsoft Defender on Windows endpoints and servers is potentially affected. The flaw is actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-22 with ransomware use confirmed, and is one of three Microsoft Defender zero-days reported as exploited, two of which were still unpatched at the time of reporting. Do: Apply Microsoft's April 2026 Patch Tuesday updates for the Defender Antimalware Platform (platform/security intelligence updates) per vendor instructions, consistent with CISA BOD 22-01 timelines for KEV entries, and note reports that two of the three exploited Defender zero-days were still unpatched, so monitor for follow-up fixes. Prioritize patching internet-reachable and high-value Windows hosts, and hunt for signs of local privilege escalation and ransomware precursor activity on systems that cannot be updated immediately. | 7.8 | 7% | KEV ransomware |
| masshundreds of millions of Windows endpoints and servers (Defender is the default antimalware on Windows) |
Full article425 words · extracted from helpnetsecurity.com · click to collapse
The security researcher who earlier this month published a proof-of-concept (PoC) exploit for a zero-day privilege escalation vulnerability in Microsoft Defender is back with two more.
The first, dubbed “RedSun,” is another privilege escalation flaw in the same platform. The second, “UnDefend,” allows a standard user to block Microsoft Defender from receiving signature updates or disable it entirely (if Microsoft pushes a major Defender update).
And, according to Huntress researchers, all three exploitation techniques have been leveraged in the wild by at least one threat actor.
The new exploits
The researcher, who goes by Chaotic Eclipse and Nightmare Eclipse, released the BlueHammer PoC on April 3, after claiming that a disclosure attempt with the Microsoft Security Response Center went nowhere.
On April 14, Microsoft pushed out security updates that fixed the vulnerability, which received the CVE-2026-33825 identifier. The researchers credited with reporting it – Zen Dodd and Yuanpei Xu – are not “Nightmare Eclipse”.
On April 16, this currently anonymous researcher published the “RedSun” and “UnDefend” PoC exploits to the same GitHub repository, which remains accessible despite a warning from the Microsoft-owned platform:

The effectiveness of the RedSun PoC has been confirmed by vulnerability analyst Will Dormann.
Attacks in the wild
Huntress researchers say that they’ve observed the BlueHammer exploit being blocked by Windows Defender on April 10. On April 16, they also observed the “RedSun” and “UnDefend” PoCs being used.
The attacker dropped the exploit files into the user’s Pictures and Downloads folders and renamed them to avoid suspicion. Then, before launching the exploits, they ran commands to map out user privileges, discovered stored credentials, and the Active Directory structure.
“Huntress has isolated the affected organization to prevent further post-exploitation,” the researchers added.
The ball is now in Microsoft’s court: with the next Patch Tuesday many weeks away, an out-of-band emergency patch looks like the most likely path forward.
UPDATE (April 21, 2026, 09:15 a.m. ET):
Huntress researchers published a more in-depth account of the above mentioned intrusion and how the three exploits work (and their limitations).
“The activity (…) appeared to be part of a broader intrusion rather than isolated proof-of-concept (PoC) testing. Huntress identified suspicious FortiGate SSL VPN access tied to the compromised environment, including a source IP geolocated to Russia, with additional suspicious infrastructure observed in other regions,” the researchers noted.
UPDATE (April 23, 2026, 05:20 a.m. ET):
CVE-2026-33825 (aka BlueHammer) has been added to CISA’s Known Exploited Vulnerabilities catalog

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/04/17/microsoft-defender-zero-days-exploited/