Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3487 articles · 157946 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-33825KEVEXPLOITEDPATCHED
microsoft · defender_antimalware_platform

Microsoft Defender Elevation of Privilege Vulnerability

Description

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
microsoftdefender_antimalware_platform4.0.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftdefendercert_advisory90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825(vendor-advisory, patch)

Related News (21 articles)

Tier E
Reddit r/cybersecurity2d ago
Microsoft vs Chaotic Eclipse: three zero-days now actively exploited
→ No new info (linked only)
Tier D
The Hacker News2d ago
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
→ No new info (linked only)
Tier D
BleepingComputer10d ago
Microsoft shares mitigation for YellowKey Windows zero-day
→ No new info (linked only)
Tier D
The Hacker News16d ago
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation
→ No new info (linked only)
Tier D
BleepingComputer17d ago
Windows BitLocker zero-day gives access to protected drives, PoC released
→ No new info (linked only)
Tier D
BleepingComputer37d ago
CISA orders feds to patch BlueHammer flaw exploited as zero-day
→ No new info (linked only)
Tier D
SecurityWeek37d ago
Recent Microsoft Defender Vulnerability Exploited as Zero-Day
→ No new info (linked only)
Tier C
Qualys Blog38d ago
Don’t Wait for a Patch. Mitigate RedSun Risk in Microsoft Defender Today 
→ No new info (linked only)
Tier B
CERT-FR40d ago
Bulletin d'actualité CERTFR-2026-ACT-018 (20 avril 2026)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity43d ago
CVE-2026-33825 deep-dive: The researcher commented out the full credential dump. Here's what that means.
→ No new info (linked only)
Tier D
CSO Online43d ago
Caught, Quarantined, Re-installed: RedSun turns Microsoft Defender on itself
→ No new info (linked only)
Tier D
Help Net Security43d ago
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild
→ No new info (linked only)
Tier D
BleepingComputer43d ago
Recently leaked Windows zero-days now exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News44d ago
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
→ No new info (linked only)
Tier B
BSI Advisories45d ago
[NEU] [mittel] Microsoft Defender: Schwachstelle ermöglicht Erlangen von Administratorrechten
→ No new info (linked only)
Tier D
CSO Online45d ago
April Patch Tuesday roundup: Zero day vulnerabilities and critical bugs
→ No new info (linked only)
Tier C
Krebs on Security45d ago
Patch Tuesday, April 2026 Edition
→ No new info (linked only)
Tier C
Cisco Talos45d ago
Microsoft Patch Tuesday for April 2026 - Snort Rule and Prominent Vulnerabilities
→ No new info (linked only)
Tier C
VulDB46d ago
CVE-2026-33825 | Microsoft insufficient granularity of access control
→ No new info (linked only)
Tier A
Microsoft MSRC46d ago
CVE-2026-33825 Microsoft Defender Elevation of Privilege Vulnerability
→ No new info (linked only)
Tier C
CrowdStrike Blog46d ago
April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
4.18.26030.3011
CWECWE-1220
PublishedApr 14, 2026
Last enriched37d agov10
Tags
zero-daylocal privilege escalationBlueHammer
Trending Score114🔥
Source articles21
Independent14
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-41091EXPKEV
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 114
MEDIUMCVE-2026-32202EXPKEV
Windows Shell Spoofing Vulnerability
Trending: 113
MEDIUMCVE-2026-45498EXPKEV
Microsoft Defender Denial of Service Vulnerability
Trending: 99
MEDIUMCVE-2026-45585EXP
Windows BitLocker Security Feature Bypass Vulnerability
Trending: 84
HIGHCVE-2026-40369EXP
Windows Kernel Elevation of Privilege Vulnerability
Trending: 60

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Added to CISA KEV
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: severity
Apr 14, 2026
Updated: description, exploitAvailable, activelyExploited
Apr 14, 2026
Updated: affectedVersions
Apr 16, 2026
Updated: description, affectedVersions
Apr 17, 2026
Updated: description
Apr 17, 2026
Updated: description, affectedVersions, cweIds
Apr 17, 2026
Updated: description, iocs
Apr 20, 2026
Updated: affectedVersions, tags
Apr 22, 2026
Updated: tags
Apr 23, 2026
Actively Exploited
May 12, 2026
Exploit Available
May 12, 2026
Patch Available
May 12, 2026

Version History

v10
Last enriched 37d ago
v10Tier D37d ago

Updated description with more technical detail, added new tag 'BlueHammer', and included suspicious IP geolocation information.

tags
via BleepingComputer
v9Tier C38d ago

Updated description with detailed technical information, changed severity to CRITICAL, added affected versions, and noted no patch is currently available.

affectedVersionstags
via Qualys Blog
v8Tier B40d ago

Updated description with CVE-2026-33825, confirmed severity as HIGH, and provided a URL for the patch.

descriptioniocs
via CERT-FR
v7Tier D43d ago

Updated description with new technical details about the RedSun exploit and added CWE-20 as a new identifier.

descriptionaffectedVersionscweIds
via CSO Online
v6Tier D43d ago

Updated description with new technical details about additional vulnerabilities and confirmed ongoing exploitation.

description
via Help Net Security
v5Tier D43d ago

Updated description with details on the BlueHammer vulnerability and its CVE-ID, added affected versions, and noted the patch availability in April 2026.

descriptionaffectedVersions
via BleepingComputer
v4Tier D44d ago

Updated description with details about the new unpatched vulnerability RedSun and added affected versions including Windows 10 and Windows 11.

affectedVersions
via The Hacker News
v3Tier C45d ago

Updated description to include the name 'BlueHammer', marked exploit as available, and noted that it is actively exploited.

descriptionexploitAvailableactivelyExploited
via Krebs on Security
v2Tier C46d ago

Updated severity to CRITICAL and noted that no exploit is available.

severity
via VulDB
v146d ago

Initial creation