logo

'BlueHammer' Windows Zero-Day Exploit Signals Microsoft Bug Disclosure Issues

ID: bff5aa0e-f739-5ad5-9ed5-fc53669571fc

STIX ID: report--bff5aa0e-f739-5ad5-9ed5-fc53669571fc

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Elizabeth Montalbano

...
...

A researcher publicly released exploit code for a Windows zero-day called "BlueHammer" that abuses a TOCTOU race condition and path confusion in Windows Defender’s signature update mechanism to read the SAM database and enable privilege escalation via pass-the-hash. The PoC reportedly works on client desktops (not reliably on servers), may be imperfect, and Microsoft had not yet patched the flaw at the time of reporting, increasing the likelihood of criminal or APT actors adapting the code for real-world attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.