logo

Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit

ID: 793308fb-d7fd-5ecb-a1b4-a322bf84a59e

STIX ID: report--793308fb-d7fd-5ecb-a1b4-a322bf84a59e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A disgruntled researcher published a public proof-of-concept called "BlueHammer" for an unpatched Windows local privilege escalation (LPE) zero-day that combines a TOCTOU and path confusion to access the Security Account Manager (SAM) and escalate to SYSTEM. The exploit code was posted on GitHub, is reportedly buggy but has been confirmed to work in at least some cases by researchers, and Microsoft had not released a patch at time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.