CVE-2026-33825
Microsoft Defender Antimalware Platform vulnerability analysis and mitigation

Overview

CVE-2026-33825 is a local privilege escalation vulnerability in Microsoft Defender caused by insufficient granularity of access control (CWE-1220). It allows an authorized attacker with low privileges to escalate to SYSTEM-level access on affected Windows systems. The vulnerability was publicly disclosed on April 14, 2026, as part of Microsoft's April Patch Tuesday, which addressed 167+ flaws. It affects Microsoft Defender Antimalware Platform versions prior to 4.18.26030.3011. The CVSS v3.1 base score is 7.8 (High) (Microsoft MSRC, CISA KEV).

Technical details

The root cause is classified as CWE-1220 (Insufficient Granularity of Access Control), where Microsoft Defender's access control policy is too broadly defined, allowing low-privileged local users to access security-sensitive resources or operations that should be restricted. The exploit technique, publicly dubbed "BlueHammer" (for the patched variant) and "RedSun" (for a related PoC), reportedly leverages a batch oplock race condition or similar Windows file system primitive to abuse Defender's privileged write operations, effectively turning the antivirus engine into a privilege escalation tool. Exploitation requires only local access with low privileges and no user interaction. Technical write-ups and PoC code were publicly released by a researcher known as "Nightmare Eclipse" shortly after patch disclosure, with detailed mechanics described in posts such as the RedSun PoC analysis (BleepingComputer, Picus Security, CloudSEK).

Impact

Successful exploitation grants an attacker SYSTEM-level privileges on the affected Windows host, resulting in full confidentiality, integrity, and availability compromise. An attacker who already has a low-privileged foothold (e.g., via phishing or initial access) can use this vulnerability to execute arbitrary code as SYSTEM, disable security controls, install persistent backdoors, and move laterally across the network. The vulnerability affects all Windows systems running unpatched versions of Microsoft Defender Antimalware Platform, potentially exposing over a billion Windows endpoints globally (CISA KEV, Tom's Guide).

Exploitation steps

  1. Initial Access: Attacker gains a low-privileged local user session on a Windows system running an unpatched version of Microsoft Defender Antimalware Platform (< 4.18.26030.3011), e.g., via phishing, credential theft, or exploitation of another vulnerability.
  2. Reconnaissance: Confirm the Defender version is vulnerable by checking MpCmdRun.exe -GetFiles output or registry key HKLM\SOFTWARE\Microsoft\Windows Defender\Signature Updates.
  3. Deploy RedSun/BlueHammer PoC: Execute the publicly released PoC exploit ("RedSun"), which abuses Defender's privileged write operations — reportedly using a batch oplock race condition to manipulate file system operations that Defender performs with SYSTEM privileges.
  4. Trigger Privilege Escalation: The exploit causes Defender's engine to write attacker-controlled content to a protected location or execute an attacker-controlled payload under the SYSTEM context, bypassing the insufficient access control boundary.
  5. Achieve SYSTEM Shell: The attacker obtains a SYSTEM-level command shell or process, enabling arbitrary code execution, credential dumping (e.g., via lsass), persistence installation, and lateral movement (BleepingComputer, Picus Security, CloudSEK).

Indicators of compromise

  • Process: Unusual child processes spawned by MsMpEng.exe (Windows Defender service) such as cmd.exe, powershell.exe, or conhost.exe with SYSTEM privileges; unexpected MpCmdRun.exe executions initiated by non-administrative users.
  • File System: Unexpected files written to protected directories (e.g., C:\Windows\System32\, C:\ProgramData\Microsoft\Windows Defender\) by low-privileged user accounts; new scheduled tasks or services created under SYSTEM context following low-privilege user activity.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 – Special privileges assigned to new logon) for non-administrative accounts; Event ID 4688 showing process creation of cmd.exe or powershell.exe with SYSTEM integrity level spawned from Defender processes.
  • Network: Outbound connections from the compromised host to unknown external IPs shortly after Defender process anomalies; lateral movement traffic (SMB, WMI, RDP) originating from previously low-privileged accounts.
  • Registry: New or modified run keys, services, or scheduled tasks created under HKLM by accounts that should not have write access; modifications to Defender exclusion lists to facilitate follow-on malware execution (Huntress, HookProbe).

Mitigation and workarounds

Microsoft released a patch on April 14, 2026 (April Patch Tuesday); affected systems should update the Microsoft Defender Antimalware Platform to version 4.18.26030.3011 or later (Microsoft MSRC). Because Defender updates are delivered automatically via Windows Update and Microsoft Update, most systems with automatic updates enabled will receive the fix without manual intervention — administrators should verify the platform version is updated. CISA mandated that U.S. federal agencies apply mitigations by May 6, 2026 per BOD 22-01 (CISA KEV). As a defense-in-depth measure, enforce the principle of least privilege to limit the number of local user accounts that could exploit this vulnerability, and monitor for suspicious privilege escalation activity.

Community reactions

The vulnerability generated significant industry attention, partly due to the controversial disclosure behavior of the researcher "Nightmare Eclipse" (also known as "Chaotic Eclipse"), who publicly released PoC exploit code before coordinating with Microsoft, leading Microsoft to initially threaten legal action before backing down following widespread community backlash (The Hacker News, BleepingComputer). Dark Reading, CSO Online, SecurityWeek, and Help Net Security all covered the active exploitation and the broader "Nightmare Eclipse" zero-day cluster (BlueHammer, RedSun, UnDefend) (Dark Reading, CSO Online). Security researchers on Reddit (r/netsec, r/cybersecurity) and Mastodon debated the ethics of the disclosure, with notable commentary from researchers including Brian Krebs and Will Dormann. Microsoft ultimately clarified it would not sue security researchers, and the incident prompted broader discussion about coordinated vulnerability disclosure norms (SecurityWeek).

Additional resources


SourceThis report was generated using AI

Related Microsoft Defender Antimalware Platform vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-41091HIGH7.8
  • Microsoft Defender Antimalware Platform logoMicrosoft Defender Antimalware Platform
  • cpe:2.3:a:microsoft:defender_antimalware_platform
YesYesMay 20, 2026
CVE-2026-33825HIGH7.8
  • Microsoft Defender Antimalware Platform logoMicrosoft Defender Antimalware Platform
  • cpe:2.3:a:microsoft:defender_antimalware_platform
YesYesApr 14, 2026
CVE-2026-45498HIGH7.5
  • Microsoft Defender Antimalware Platform logoMicrosoft Defender Antimalware Platform
  • cpe:2.3:a:microsoft:defender_antimalware_platform
YesYesMay 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management