logo

BlueHammer: Windows zero-day exploit leaked

ID: 72a4f03c-220e-5df9-a052-7426f4cb99d8

STIX ID: report--72a4f03c-220e-5df9-a052-7426f4cb99d8

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-04-08

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

A published PoC named BlueHammer leverages Microsoft Defender's update workflow and Volume Shadow Copy snapshots to steal local NTLM hashes, change and then restore Administrator passwords, and escalate from a standard user to NT AUTHORITY\\SYSTEM on Windows 10/11 and Windows Server; researchers corrected the PoC and validated the technique, Microsoft has been notified but no patch has been released. Organizations are advised to hunt for behavioral indicators (VSS enumeration from user-space, unexpected Cloud Files sync root registrations, service creation by low-privileged accounts) and enforce least privilege until a fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.