Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Three Microsoft Defender Zero-Days Actively Exploited; Two
Three Microsoft Defender Zero-Days Actively Exploited; Two
NEWS

Three Microsoft Defender Zero-Days Actively Exploited; Two

Huntress is warning that threat actors are actively exploiting three privilege escalation vulnerabilities in Microsoft Defender — codenamed BlueHammer,...

Dylan H.

News Desk

April 17, 2026
3 min read

Overview

Security firm Huntress is sounding the alarm over three actively exploited zero-day vulnerabilities in Microsoft Defender, Microsoft's built-in endpoint protection platform. The flaws — internally codenamed BlueHammer, RedSun, and a third undisclosed vulnerability — allow attackers with standard user access to escalate privileges on compromised Windows systems.

As of April 17, 2026, two of the three vulnerabilities remain unpatched, leaving a significant window of exposure across Windows environments globally.

The Three Vulnerabilities

BlueHammer

The BlueHammer vulnerability leverages a flaw in Microsoft Defender's real-time protection engine to execute arbitrary code with SYSTEM privileges. Huntress has noted that BlueHammer requires a GitHub account to view full technical details, suggesting coordinated responsible disclosure is still in progress. The vulnerability was previously disclosed in leaked exploit code that surfaced in early April 2026.

RedSun

RedSun targets the Microsoft Defender antimalware service executable (MsMpEng.exe). Exploiting a race condition in the service's file quarantine logic, attackers can hijack the quarantine process to overwrite arbitrary files with attacker-controlled content, enabling privilege escalation to SYSTEM. Huntress confirmed active exploitation of RedSun in the wild.

Third Unidentified Flaw

A third vulnerability has been reported by Huntress but details remain limited pending further disclosure coordination with Microsoft. Active exploitation has been observed alongside BlueHammer and RedSun in multi-stage attack chains.

Active Exploitation

Huntress researchers have observed threat actors chaining these Defender zero-days as post-exploitation tools following initial access via phishing or vulnerability exploitation. The privilege escalation achieved enables attackers to:

  • Disable endpoint detection and response (EDR) tools
  • Establish persistent SYSTEM-level backdoors
  • Laterally move across enterprise networks with elevated credentials

The attacks have been observed targeting enterprise environments across North America and Europe, with particular focus on organizations running unmanaged Windows 11 endpoints.

Microsoft Response

Microsoft has acknowledged the reports but has only issued a patch for one of the three vulnerabilities as of this writing. The company has indicated that patches for BlueHammer and the third unidentified flaw are in development, with no specific timeline provided.

A Microsoft spokesperson stated: "We are aware of the reports and are working to address the remaining issues as quickly as possible. We encourage customers to apply available updates immediately."

Recommendations

Given that two vulnerabilities remain unpatched, organizations should take the following interim mitigations:

  1. Apply available patches immediately — Install all pending Windows and Defender updates via Windows Update.
  2. Enable attack surface reduction (ASR) rules — Configure ASR rules in Microsoft Defender to limit attacker post-exploitation options.
  3. Monitor for privilege escalation — Review SIEM alerts for unexpected SYSTEM-level process creation from user sessions.
  4. Restrict local administrator accounts — Apply the principle of least privilege and remove unnecessary local admin rights.
  5. Deploy additional EDR coverage — Consider supplementary endpoint detection for environments where Defender is the sole protection layer.

References

  • The Hacker News: Three Microsoft Defender Zero-Days Actively Exploited
  • Huntress Threat Intelligence
  • Microsoft Security Response Center

Related Reading

  • Microsoft Warns of Two Actively Exploited Defender
  • Disgruntled Researcher Leaks BlueHammer Windows Zero-Day
  • Microsoft Links Storm-1175 to Medusa Ransomware Zero-Day
#Zero-Day#Microsoft#Privilege Escalation#Windows Defender#Threat Intelligence

Related Articles

Microsoft Warns of Two Actively Exploited Defender

Microsoft has disclosed two Windows Defender vulnerabilities under active exploitation in the wild, including CVE-2026-41091 — a privilege escalation flaw...

5 min read

Microsoft Warns of New Defender Zero-Days Exploited in

Microsoft has issued emergency patches for two Windows Defender vulnerabilities that were actively exploited as zero-days before fixes were available....

5 min read

MiniPlasma Windows 0-Day Enables SYSTEM Privilege

A new Windows kernel privilege escalation zero-day dubbed MiniPlasma, released by researcher Chaotic Eclipse, grants SYSTEM-level access on fully patched...

5 min read
Back to all News