logo

BlueHammer Windows Zero-Day: Privilege Escalation Risk

ID: e48d4fef-7062-5b14-b2fc-16c09c11df95

STIX ID: report--e48d4fef-7062-5b14-b2fc-16c09c11df95

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

BlueHammer is an unpatched Windows local privilege-escalation zero-day that abuses time-of-check/time-of-use and path confusion to elevate a low-privileged account to NT AUTHORITY\SYSTEM; public release of exploit code increases the operational risk despite some reliability inconsistencies, so organizations should tighten least-privilege, restrict local admin rights, and enhance endpoint monitoring until a patch is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.