📣 Send us your press release
Site updates every 15 minutes
Technology

Windows Defender CVE-2026-33825 Zero-Day Vulnerability Detailed

A zero-day vulnerability in Windows Defender, CVE-2026-33825, was publicly disclosed with a "BlueHammer" exploit, enabling local privilege escalation on patched systems.

11 October 2026
Windows Defender CVE-2026-33825 Zero-Day Vulnerability Detailed

Picus Security, a cybersecurity firm, has detailed a zero-day vulnerability affecting Microsoft Defender, tracked as CVE-2026-33825. Publicly disclosed on April 7, 2026, the vulnerability allowed for local privilege escalation, granting SYSTEM-level access to unprivileged users on fully patched Windows 10 and Windows 11 systems.

The exploit, referred to as "BlueHammer," was released before an official fix was available, marking it as a true zero-day at the time. The flaw originates from a race condition within Windows Defender's file remediation logic. Attackers could exploit this by manipulating the filesystem to redirect Defender's operations, potentially overwriting critical system files.

According to Picus Security, CVE-2026-33825 is part of a broader series of zero-day vulnerabilities targeting Windows Defender disclosed in April 2026. These included "BlueHammer" for privilege escalation, "UnDefend" which disrupted the update mechanism, and "RedSun," another privilege escalation technique. These findings highlight systemic weaknesses in Defender's architecture.

Successful exploitation could lead to SYSTEM-level code execution. Picus Security strongly advises organizations to immediately apply the April 2026 security updates to address CVE-2026-33825 and mitigate associated risks.

Original source: picussecurity.com