Microsoft Defender 0-Day Vulnerability “RedSun” Enables Full SYSTEM Access
ID: 032b2cb6-7633-518a-9570-68c1a011fbd4
STIX ID: report--032b2cb6-7633-518a-9570-68c1a011fbd4
Feed Name: cybersecurityNews.com
A researcher published details of a zero-day Microsoft Defender local privilege escalation named "RedSun" that leverages Defender's cloud file handling (cldapi.dll), opportunistic locks, and NTFS junctions to overwrite system binaries in C:\Windows\System32 and achieve SYSTEM-level execution on patched Windows 10/11 and Server 2019+. The flaw is unpatched, reportedly reliable (~100%), affects broad Windows versions, and security teams are advised to monitor Defender file-restoration activity and implement detection rules until a Microsoft fix is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
