logo

New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges

ID: e54a1ed0-f82a-5d6d-8366-380012fbe09f

STIX ID: report--e54a1ed0-f82a-5d6d-8366-380012fbe09f

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A researcher published a public proof-of-concept for "RedSun," a Microsoft Defender local privilege escalation zero-day that abuses the Cloud Files API, an EICAR payload, an oplock race, and a directory junction to overwrite and execute TieringEngineService.exe, granting SYSTEM on fully patched Windows 10/11 and Server; the exploit has been independently confirmed and was released alongside criticism of Microsoft's handling of vulnerability disclosures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.