Don’t Wait for a Patch. Mitigate RedSun Zero-Day Risk in Microsoft Defender Today
ID: 44358496-5d0d-5352-b650-3620f39db147
STIX ID: report--44358496-5d0d-5352-b650-3620f39db147
Feed Name: Qualys Blog
Threat Score
RedSun is a critical zero-day local privilege escalation in Microsoft Defender that enables a low-privileged user to escalate to NT AUTHORITY\SYSTEM by manipulating Defender's cloud-file restoration logic; no vendor patch exists, Qualys VMDR provides detection (QID 92382), and Qualys TruRisk™ Eliminate offers immediate, script-based mitigations (e.g., disabling the Cloud Files Mini Filter) to remove exploitability and provide auditable risk reduction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
