logo

Microsoft Defender Flaws Exploited on Windows, Two Left Unpatched

ID: 4b65822d-f07e-5340-b45f-7b9faa370e21

STIX ID: report--4b65822d-f07e-5340-b45f-7b9faa370e21

Feed Name: TechRepublic Security

Threat Score
80/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: J.R. Johnivan

...
...

A security researcher (Chaotic Eclipse / Nightmare-Eclipse) published zero-day exploits for three Microsoft Defender flaws: BlueHammer (patched) abuses Defender definition updates and opportunistic locks to escalate local accounts to SYSTEM; RedSun (unpatched) uses the Cloud Files API and oplocks to overwrite System32 files for SYSTEM access across Windows 10/11 and several Server versions; and UnDefend (unpatched) can deny Microsoft Defender definition updates or disable Defender during major platform updates. Microsoft has patched BlueHammer but RedSun and UnDefend remain unpatched, and organizations are advised to monitor Defender activity until fixes are released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.