
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33825 is a local privilege escalation vulnerability in Microsoft Defender caused by insufficient granularity of access control (CWE-1220). It allows an authorized attacker with low privileges to escalate to SYSTEM-level access on affected Windows systems. The vulnerability was publicly disclosed on April 14, 2026, as part of Microsoft's April Patch Tuesday, which addressed 167+ flaws. It affects Microsoft Defender Antimalware Platform versions prior to 4.18.26030.3011. The CVSS v3.1 base score is 7.8 (High) (Microsoft MSRC, CISA KEV).
The root cause is classified as CWE-1220 (Insufficient Granularity of Access Control), where Microsoft Defender's access control policy is too broadly defined, allowing low-privileged local users to access security-sensitive resources or operations that should be restricted. The exploit technique, publicly dubbed "BlueHammer" (for the patched variant) and "RedSun" (for a related PoC), reportedly leverages a batch oplock race condition or similar Windows file system primitive to abuse Defender's privileged write operations, effectively turning the antivirus engine into a privilege escalation tool. Exploitation requires only local access with low privileges and no user interaction. Technical write-ups and PoC code were publicly released by a researcher known as "Nightmare Eclipse" shortly after patch disclosure, with detailed mechanics described in posts such as the RedSun PoC analysis (BleepingComputer, Picus Security, CloudSEK).
Successful exploitation grants an attacker SYSTEM-level privileges on the affected Windows host, resulting in full confidentiality, integrity, and availability compromise. An attacker who already has a low-privileged foothold (e.g., via phishing or initial access) can use this vulnerability to execute arbitrary code as SYSTEM, disable security controls, install persistent backdoors, and move laterally across the network. The vulnerability affects all Windows systems running unpatched versions of Microsoft Defender Antimalware Platform, potentially exposing over a billion Windows endpoints globally (CISA KEV, Tom's Guide).
MpCmdRun.exe -GetFiles output or registry key HKLM\SOFTWARE\Microsoft\Windows Defender\Signature Updates.lsass), persistence installation, and lateral movement (BleepingComputer, Picus Security, CloudSEK).MsMpEng.exe (Windows Defender service) such as cmd.exe, powershell.exe, or conhost.exe with SYSTEM privileges; unexpected MpCmdRun.exe executions initiated by non-administrative users.C:\Windows\System32\, C:\ProgramData\Microsoft\Windows Defender\) by low-privileged user accounts; new scheduled tasks or services created under SYSTEM context following low-privilege user activity.cmd.exe or powershell.exe with SYSTEM integrity level spawned from Defender processes.HKLM by accounts that should not have write access; modifications to Defender exclusion lists to facilitate follow-on malware execution (Huntress, HookProbe).Microsoft released a patch on April 14, 2026 (April Patch Tuesday); affected systems should update the Microsoft Defender Antimalware Platform to version 4.18.26030.3011 or later (Microsoft MSRC). Because Defender updates are delivered automatically via Windows Update and Microsoft Update, most systems with automatic updates enabled will receive the fix without manual intervention — administrators should verify the platform version is updated. CISA mandated that U.S. federal agencies apply mitigations by May 6, 2026 per BOD 22-01 (CISA KEV). As a defense-in-depth measure, enforce the principle of least privilege to limit the number of local user accounts that could exploit this vulnerability, and monitor for suspicious privilege escalation activity.
The vulnerability generated significant industry attention, partly due to the controversial disclosure behavior of the researcher "Nightmare Eclipse" (also known as "Chaotic Eclipse"), who publicly released PoC exploit code before coordinating with Microsoft, leading Microsoft to initially threaten legal action before backing down following widespread community backlash (The Hacker News, BleepingComputer). Dark Reading, CSO Online, SecurityWeek, and Help Net Security all covered the active exploitation and the broader "Nightmare Eclipse" zero-day cluster (BlueHammer, RedSun, UnDefend) (Dark Reading, CSO Online). Security researchers on Reddit (r/netsec, r/cybersecurity) and Mastodon debated the ethics of the disclosure, with notable commentary from researchers including Brian Krebs and Will Dormann. Microsoft ultimately clarified it would not sue security researchers, and the incident prompted broader discussion about coordinated vulnerability disclosure norms (SecurityWeek).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."