Researcher Released Windows Defender 0-Day Exploit Code, Allowing Attackers to Gain Full Access
ID: 3c41f2b5-b05d-53cb-8e81-5bd55381e8b6
STIX ID: report--3c41f2b5-b05d-53cb-8e81-5bd55381e8b6
Feed Name: cybersecurityNews.com
Threat Score
A researcher released BlueHammer, a working Windows zero-day local privilege escalation PoC that elevates low-privileged accounts to NT AUTHORITY\SYSTEM and can reveal NTLM password hashes; the release was uncoordinated due to disputes with Microsoft’s security response process and no official patch or CVE was available at publication, creating immediate risk of weaponization by ransomware groups or APTs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
