Two Windows Defender privilege escalations seen in real attacks
A researcher using the alias Chaotic/Nightmare Eclipse has published details of two local privilege escalation flaws in Windows, both tied to Microsoft Defender. The first, called Bluehammer, abuses Defender's update mechanism to reach a temporary snapshot containing the SAM database and its credentials. It is tracked as CVE-2026-33825 with a CVSS score of 7.8 and is fixed in Microsoft's April security updates. The second, RedSun, abuses how cloud file tags are handled to make Defender write attacker-controlled code into System32. The same author has also released UnDefend, a tool that blocks Defender signature updates. Huntress Labs reports all three are now being used in the wild.
What this means for your organisation
This is not about how an attacker gets in, but about what happens next. Once someone has a foothold on a workstation, these techniques hand them system rights and local password hashes, which shortens the path to other machines and, in the worst case, to the domain. The fact that the security product itself is the lever weakens a control most executives assume is solid.
Berigo recommends
- Deploy Microsoft's April updates across workstations, not only servers.
- Monitor for Defender signature updates that quietly stop on individual machines, and treat that as an incident.
- Restrict local administrator rights so a foothold on a client gives an attacker little to build on.
- Verify that endpoint logs actually reach somewhere outside the machine being compromised.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch