logo

Three Zero-day Vulnerabilities in Microsoft Windows [Blog]

ID: ba114811-ad1f-5e5b-b609-7d3387794f4c

STIX ID: report--ba114811-ad1f-5e5b-b609-7d3387794f4c

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

### Executive Summary A security researcher released three Windows zero-day POCs: angrypolarbearbug2 and bearlpe (local privilege escalation bugs that can grant SYSTEM) and sandboxescape (an IE11 sandbox bypass requiring DLL injection). The issues were tested on Windows 10 and IE11, remain unpatched by Microsoft at the time of reporting, and receive detection coverage from Zscaler.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.