CVE detail
CVE-2026-33825
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 2
- highest bucket
Evidence
Source links by recency
34 source links · newest first
ploit targeting Microsoft Defender that leads to local privilege escalation. Chaotic Eclipse also disclosed BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498), and RedSun (CVE-2026-41091) zero-days. The disclosures are believed to stem from a dispute with Microsoft over the vulnerability reporting process. In early June, Chaotic Eclipse released a
newssecurityaffairs.comJul 15, 2026, 4:57 PM- Microsoft Reins in RoguePlanet Zero-Day ThreatDark Reading
t issued an out-of-band patch for RoguePlanet , an elevation-of-privilege vulnerability in Windows Defender, tracked as CVE-2026-50656. The high-severity flaw, which received a 7.8 CVSS score from Microsoft, could allow an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, which would give them com
newswww.darkreading.comJul 9, 2026, 8:21 PM The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update.
newswww.securityweek.comJul 9, 2026, 10:28 AMCISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to gain SYSTEM privileges through Microsoft Defender. BlueHammer, tracked as CVE-2026-33825, has moved from proof-of-concept noise to real ransomware attacks in the wild, the US CISA confirms. BlueHammer allows attackers to escalate privileges locally in Microsoft Defender. The vulnerability, along with two other zero-days dubbed […]
newssecurityaffairs.comJul 1, 2026, 11:26 AMThe Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released.
newswww.securityweek.comJun 30, 2026, 1:56 PMMicrosoft says it’s working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
newswww.malwarebytes.comJun 18, 2026, 12:58 PMMicrosoft confirmed the RoguePlanet Defender zero-day (CVE-2026-50656), a privilege escalation flaw, and is developing a security patch. Microsoft has acknowledged the RoguePlanet zero-day affecting Microsoft Defender, tracked as CVE-2026-50656 (CVSS score of 7.8). The vulnerability allows privilege escalation through the Microsoft Malware Protection Engine. The company stated it is aware of the issue and is […]
newssecurityaffairs.comJun 18, 2026, 9:21 AMThe public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.
newswww.securityweek.comJun 17, 2026, 9:41 AM- Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of ResearchSecurity Affairs
GreatXML bypasses BitLocker via Defender offline scan artifacts, giving SYSTEM shell in Recovery Mode. No patch exists. Any machine that ran an offline scan is vulnerable. On June 10, security researcher Chaotic Eclipse (aka Nightmare Eclipse) published a new working exploit dubbed GreatXML that bypasses BitLocker and opens a command shell with full SYSTEM privileges […]
newssecurityaffairs.comJun 11, 2026, 10:58 AM Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.
newswww.securityweek.comJun 10, 2026, 11:44 AMThe researcher Chaotic Eclipse released a PoC for the RoguePlanet Microsoft Defender zero-day, which can grant SYSTEM privileges on fully patched Windows systems. Security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, has published a new proof-of-concept exploit for a RoguePlanet Microsoft Defender zero-day. The flaw relies on a race condition that can provide attackers with […]
newssecurityaffairs.comJun 10, 2026, 9:45 AMy to respond without out-of-cycle patches. At time of writing, Microsoft has provided mitigation advice and patches for CVE-2026-33825 , CVE-2026-45585 , CVE-2026-45498 , and CVE-2026-41091 , leaving only two elevation of privilege vulnerabilities unpatched, known as MiniPlasma and GreenPlasma. However, a recent blog post by Nightmare Eclipse with the
vendorwww.rapid7.comJun 9, 2026, 9:04 PMbe the flaw known as Bitskrieg and a collaboration between Chaotic Eclipse (Nightmare Eclipse) and Jonas L . Important CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability CVE-2026-49160 is a denial of service (DoS) vulnerability affecting HTTP.sys. It received a CVSSv3 score of 7.5 and is rated as important. It was assessed as “Exploitation More
vendorwww.tenable.comJun 9, 2026, 6:19 PMMicrosoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.
newswww.securityweek.comJun 3, 2026, 9:57 AM- Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)Help Net Security
Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog. The vulnerabilities CVE-2026-41091 allows for local privilege elevation (LPE), and is caused by the Microsoft Malware Protection Engine improperly resolving links before accessing files. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft noted. CVE-2026-45498 can cause a denial-of-service (DoS) state, i.e., it can be used to prevent … More →
newswww.helpnetsecurity.comMay 21, 2026, 10:57 AM An old elevation-of-privilege (EoV) vulnerability affecting the Cloud Filter driver “cldflt.sys” in Windows has come back to haunt Microsoft, as researchers claim it is still exploitable six years after it was supposedly patched. The flaw, originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020, was recently picked up by Nightmare […]
newswww.csoonline.comMay 18, 2026, 12:04 PM- Chaotic Eclipse discloses MiniPlasma zero-day, suggesting a missing or undone 2020 Windows security fixSecurity Affairs
MiniPlasma: a Windows SYSTEM privilege escalation believed patched in 2020 (CVE-2020-17103) is still fully working on every patched Windows 11. Once again, security researcher Chaotic Eclipse has released a proof-of-concept exploit for a new Windows privilege escalation zero-day called MiniPlasma, which can grant attackers SYSTEM privileges on fully patched systems. The flaw affects “cldflt.sys,” the […]
newssecurityaffairs.comMay 18, 2026, 8:13 AM - Researchers uncover YellowKey and GreenPlasma Windows Zero-DaysSecurity Affairs
Researchers disclosed two new Windows zero-days named YellowKey and GreenPlasma affecting BitLocker and the CTFMON framework. A security researcher known as Chaotic Eclipse, also called Nightmare-Eclipse, disclosed two new Windows zero-day vulnerabilities named YellowKey and GreenPlasma. The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON). YellowKey could allow attackers to bypass BitLocker protections, […]
newssecurityaffairs.comMay 15, 2026, 6:46 AM Microsoft May 2026 Patch Tuesday is now live: Many fixes, but no zero-days Project Glasswing. This is one of three major security industry changes I’ll cover today. The Anthropic Mythos vulnerability discovery model has already proven to be game changing in its ability to identify new vulnerabilities in software. Many of these vulnerabilities have existed for 10 to 15 years without human discovery. In a recent announcement from Mozilla, they discovered 271 vulnerabilities when running … More →
newswww.helpnetsecurity.comMay 8, 2026, 6:19 AMAdded FAQ information. This is an informational change only.
vendormsrc.microsoft.comApr 30, 2026, 2:00 PM- U.S. CISA adds a flaw in Microsoft Defender to its Known Exploited Vulnerabilities catalogSecurity Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Microsoft Defender to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Microsoft Defender, tracked as CVE-2026-33825 (CVSS score of 7.8), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-33825 is a Microsoft Defender flaw that can be exploited […]
newssecurityaffairs.comApr 23, 2026, 9:23 AM The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges.
newswww.securityweek.comApr 23, 2026, 8:00 AM- 20th April – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 20th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Booking.com, the Amsterdam-based travel platform, has confirmed a data breach after unauthorized parties accessed reservation data linked to some customers. Exposed information included names, email addresses, phone numbers, physical addresses, and booking […]
vendorresearch.checkpoint.comApr 20, 2026, 2:24 PM - Microsoft Defender under attack as three zero-days, two of them still unpatched, enable elevated accessSecurity Affairs
Attackers exploit three Microsoft Defender zero-days, code-named BlueHammer, RedSun, and UnDefend, to gain elevated access. Attackers are exploiting three recently disclosed zero-day flaws in Microsoft Defender to gain higher privileges on compromised systems. The vulnerabilities, called BlueHammer, RedSun, and UnDefend, were revealed by a researcher known as Chaotic Eclipse after criticizing Microsoft’s handling of the […]
newssecurityaffairs.comApr 18, 2026, 6:49 AM Days after Microsoft patched a high-severity issue affecting its Windows Defender antivirus tool through April’s Patch Tuesday, researchers warn of another vulnerability that could enable SYSTEM privileges through local escalation. In a newly disclosed proof-of-concept (PoC) exploit, dubbed “RedSun,” GitHub user going by the name “Nightmare Eclipse” demonstrated how Microsoft Defender’s handling of certain cloud-tagged […]
newswww.csoonline.comApr 17, 2026, 11:55 AM- Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wildHelp Net Security
The security researcher who earlier this month published a proof-of-concept (PoC) exploit for a zero-day privilege escalation vulnerability in Microsoft Defender is back with two more. The first, dubbed “RedSun,” is another privilege escalation flaw in the same platform. The second, “UnDefend,” allows a standard user to block Microsoft Defender from receiving signature updates or disable it entirely (if Microsoft pushes a major Defender update). And, according to Huntress researchers, all three exploitation techniques have … More →
newswww.helpnetsecurity.comApr 17, 2026, 10:04 AM This month’s Patch Tuesday addresses 167 vulnerabilities, including two zero-days that could lead to system compromise, data exposure, and privilege escalation.
newswww.malwarebytes.comApr 15, 2026, 9:57 AMMicrosoft Patch Tuesday security updates for April 2026 fixed 165 vulnerabilities, including an actively exploited SharePoint zero-day. Microsoft Patch Tuesday security updates addressed 165 vulnerabilities, making it one of the largest updates by CVE count. One of the most interesting flaws fixed by the IT giant is a critical SharePoint zero-day, tracked as CVE-2026-32201, already […]
newssecurityaffairs.comApr 15, 2026, 5:18 AMA critical hole in Windows Internet Key Exchange for secure communications, an actively exploited zero day in Microsoft SharePoint and a critical SQL injection vulnerability in a SAP product are the focus of the April Patch Tuesday releases requiring immediate attention from IT security teams. “April’s threat landscape is defined by immediate, real-world exploitation rather […]
newswww.csoonline.comApr 15, 2026, 1:27 AM- https://www.huntress.com/blog/nightmare-eclipse-intrusionwww.huntress.com
No excerpt available.
Exploitwww.huntress.comApr 14, 2026, 6:17 PM No excerpt available.
Mitigationwww.cisa.govApr 14, 2026, 6:17 PMExperts say this is the second-largest Microsoft Patch Tuesday ever based on CVE count.
newswww.securityweek.comApr 14, 2026, 6:14 PM- The April 2026 Security Update ReviewZero Day Initiative
at some of the more interesting updates for this month, starting with the vulnerability being exploited in the wild: - CVE-2026-32201 - Microsoft SharePoint Server Spoofing Vulnerability Microsoft doesn’t provide a lot of information about this bug, but Spoofing bugs in SharePoint often manifest as cross-site scripting (XSS) bugs. They do note that at
vendorwww.thezdi.comApr 14, 2026, 5:49 PM - BlueHammer: Windows zero-day exploit leakedHelp Net Security
A buggy but functional proof-of-concept (PoC) exploit for an unpatched Windows local privilege escalation vulnerability dubbed BlueHammer has been published on GitHub by someone who goes by the handle Chaotic Eclipse and Nightmare Eclipse. Several security researchers have fixed the bugs in the exploit and made it work on patched Windows 10, 11, and Windows Server systems, and the question now is whether Microsoft is planning or working on a fix. The BlueHammer PoC exploit … More →
newswww.helpnetsecurity.comApr 8, 2026, 7:48 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16560CVSS 5.3 · Medium
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call…
- CVE-2026-50502CVSS 8.0 · High
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
- CVE-2026-50405CVSS 7.8 · High
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
- CVE-2026-56155CVSS 7.8 · High
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-55006CVSS 7.8 · High
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-49170CVSS 7.8 · High
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.