logo

Microsoft Defender 0-Day Vulnerability “RedSun” Enables Full SYSTEM Access

ID: 032b2cb6-7633-518a-9570-68c1a011fbd4

STIX ID: report--032b2cb6-7633-518a-9570-68c1a011fbd4

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-17

Date Updated: 2026-05-05

Author: Guru Baran

...
...

A researcher published details of a zero-day Microsoft Defender local privilege escalation named "RedSun" that leverages Defender's cloud file handling (cldapi.dll), opportunistic locks, and NTFS junctions to overwrite system binaries in C:\Windows\System32 and achieve SYSTEM-level execution on patched Windows 10/11 and Server 2019+. The flaw is unpatched, reportedly reliable (~100%), affects broad Windows versions, and security teams are advised to monitor Defender file-restoration activity and implement detection rules until a Microsoft fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.