logo

Don’t Wait for a Patch. Mitigate RedSun Zero-Day Risk in Microsoft Defender Today 

ID: 44358496-5d0d-5352-b650-3620f39db147

STIX ID: report--44358496-5d0d-5352-b650-3620f39db147

Feed Name: Qualys Blog

Threat Score
78/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

Author: Mukesh Choudhary

...
...

RedSun is a critical zero-day local privilege escalation in Microsoft Defender that enables a low-privileged user to escalate to NT AUTHORITY\SYSTEM by manipulating Defender's cloud-file restoration logic; no vendor patch exists, Qualys VMDR provides detection (QID 92382), and Qualys TruRisk™ Eliminate offers immediate, script-based mitigations (e.g., disabling the Cloud Files Mini Filter) to remove exploitability and provide auditable risk reduction.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.