BlueHammer: Windows zero-day exploit leaked
ID: 72a4f03c-220e-5df9-a052-7426f4cb99d8
STIX ID: report--72a4f03c-220e-5df9-a052-7426f4cb99d8
Feed Name: Help Net Security
A published PoC named BlueHammer leverages Microsoft Defender's update workflow and Volume Shadow Copy snapshots to steal local NTLM hashes, change and then restore Administrator passwords, and escalate from a standard user to NT AUTHORITY\\SYSTEM on Windows 10/11 and Windows Server; researchers corrected the PoC and validated the technique, Microsoft has been notified but no patch has been released. Organizations are advised to hunt for behavioral indicators (VSS enumeration from user-space, unexpected Cloud Files sync root registrations, service creation by low-privileged accounts) and enforce least privilege until a fix is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
