Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5032 articles · 189038 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-33825KEVEXPLOITEDPATCHED
microsoft · defender_antimalware_platform

Microsoft Defender Elevation of Privilege Vulnerability

Description

The vulnerability leverages a race condition, enabling an attacker to escalate privileges to System.

Affected Products

VendorProductVersions
microsoftdefender_antimalware_platform4.0.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftdefendercert_advisory90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825(vendor-advisory, patch)

Related News (32 articles)

Tier D
BleepingComputer1d ago
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
→ No new info (linked only)
Tier D
SecurityWeek34d ago
Microsoft Patches Defender ‘RoguePlanet’ Vulnerability
→ No new info (linked only)
Tier D
The Hacker News41d ago
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
→ No new info (linked only)
Tier D
SecurityWeek43d ago
BlueHammer Vulnerability Exploited in Ransomware Attacks
→ No new info (linked only)
Tier D
BleepingComputer43d ago
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
→ No new info (linked only)
Tier D
SecurityWeek56d ago
Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day
→ No new info (linked only)
Tier D
SecurityWeek63d ago
New Windows Zero-Day Exploit ‘RoguePlanet’ Released
→ No new info (linked only)
Tier D
BleepingComputer63d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
→ No new info (linked only)
Tier C
Rapid7 Blog63d ago
Patch Tuesday - June 2026
→ No new info (linked only)
Tier D
SecurityWeek70d ago
Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash
→ No new info (linked only)
Tier D
BleepingComputer72d ago
Critical Windows Netlogon RCE flaw now exploited in attacks
→ No new info (linked only)
Tier E
Reddit r/cybersecurity76d ago
Microsoft vs Chaotic Eclipse: three zero-days now actively exploited
→ No new info (linked only)
Tier D
The Hacker News76d ago
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
→ No new info (linked only)
Tier D
BleepingComputer84d ago
Microsoft shares mitigation for YellowKey Windows zero-day
→ No new info (linked only)
Tier D
The Hacker News90d ago
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation
→ No new info (linked only)
Tier D
BleepingComputer91d ago
Windows BitLocker zero-day gives access to protected drives, PoC released
→ No new info (linked only)
Tier D
BleepingComputer111d ago
CISA orders feds to patch BlueHammer flaw exploited as zero-day
→ No new info (linked only)
Tier D
SecurityWeek111d ago
Recent Microsoft Defender Vulnerability Exploited as Zero-Day
→ No new info (linked only)
Tier C
Qualys Blog112d ago
Don’t Wait for a Patch. Mitigate RedSun Risk in Microsoft Defender Today 
→ No new info (linked only)
Tier B
CERT-FR114d ago
Bulletin d'actualité CERTFR-2026-ACT-018 (20 avril 2026)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity117d ago
CVE-2026-33825 deep-dive: The researcher commented out the full credential dump. Here's what that means.
→ No new info (linked only)
Tier D
CSO Online117d ago
Caught, Quarantined, Re-installed: RedSun turns Microsoft Defender on itself
→ No new info (linked only)
Tier D
Help Net Security117d ago
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild
→ No new info (linked only)
Tier D
BleepingComputer117d ago
Recently leaked Windows zero-days now exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News118d ago
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
→ No new info (linked only)
Tier B
BSI Advisories119d ago
[NEU] [mittel] Microsoft Defender: Schwachstelle ermöglicht Erlangen von Administratorrechten
→ No new info (linked only)
Tier D
CSO Online119d ago
April Patch Tuesday roundup: Zero day vulnerabilities and critical bugs
→ No new info (linked only)
Tier C
Krebs on Security119d ago
Patch Tuesday, April 2026 Edition
→ No new info (linked only)
Tier C
Cisco Talos119d ago
Microsoft Patch Tuesday for April 2026 - Snort Rule and Prominent Vulnerabilities
→ No new info (linked only)
Tier C
VulDB120d ago
CVE-2026-33825 | Microsoft insufficient granularity of access control
→ No new info (linked only)
Tier A
Microsoft MSRC120d ago
CVE-2026-33825 Microsoft Defender Elevation of Privilege Vulnerability
→ No new info (linked only)
Tier C
CrowdStrike Blog120d ago
April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
null
CWECWE-1220
PublishedApr 14, 2026
Last enriched34d agov14
Tags
zero-daylocal privilege escalationBlueHammerRoguePlanetransomwareCISAKnown Exploited Vulnerabilitiesransomware gangs
Trending Score132🔥
Source articles32
Independent15
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 153
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 152
HIGHCVE-2026-45659EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 151
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 96
CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 75

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Added to CISA KEV
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: severity
Apr 14, 2026
Updated: description, exploitAvailable, activelyExploited
Apr 14, 2026
Updated: affectedVersions
Apr 16, 2026
Updated: description, affectedVersions
Apr 17, 2026
Updated: description
Apr 17, 2026
Updated: description, affectedVersions, cweIds
Apr 17, 2026
Updated: description, iocs
Apr 20, 2026
Updated: affectedVersions, tags
Apr 22, 2026
Updated: tags
Apr 23, 2026
Updated: tags
Jun 10, 2026
Actively Exploited
Jun 19, 2026
Exploit Available
Jun 19, 2026
Patch Available
Jun 19, 2026
Updated: description, tags
Jun 30, 2026
Updated: description, tags, patchAvailable
Jun 30, 2026
Updated: description
Jul 9, 2026

Version History

v14
Last enriched 34d ago
v14Tier D34d ago

Updated description to include details about the race condition and the official CVE ID CVE-2026-50656.

description
via SecurityWeek
v13Tier D43d ago

Updated description with more technical detail, added new tags related to CISA and ransomware gangs, and noted that the patch is no longer available.

descriptiontagspatchAvailable
via BleepingComputer
v12Tier D43d ago

Added more technical detail to the description and updated tags to include 'BlueHammer' and 'ransomware'.

descriptiontags
via BleepingComputer
v11Tier D63d ago

Added new tag 'RoguePlanet' related to the Microsoft Defender zero-day exploit.

tags
via BleepingComputer
v10Tier D111d ago

Updated description with more technical detail, added new tag 'BlueHammer', and included suspicious IP geolocation information.

tags
via BleepingComputer
v9Tier C112d ago

Updated description with detailed technical information, changed severity to CRITICAL, added affected versions, and noted no patch is currently available.

affectedVersionstags
via Qualys Blog
v8Tier B114d ago

Updated description with CVE-2026-33825, confirmed severity as HIGH, and provided a URL for the patch.

descriptioniocs
via CERT-FR
v7Tier D117d ago

Updated description with new technical details about the RedSun exploit and added CWE-20 as a new identifier.

descriptionaffectedVersionscweIds
via CSO Online
v6Tier D117d ago

Updated description with new technical details about additional vulnerabilities and confirmed ongoing exploitation.

description
via Help Net Security
v5Tier D117d ago

Updated description with details on the BlueHammer vulnerability and its CVE-ID, added affected versions, and noted the patch availability in April 2026.

descriptionaffectedVersions
via BleepingComputer
v4Tier D118d ago

Updated description with details about the new unpatched vulnerability RedSun and added affected versions including Windows 10 and Windows 11.

affectedVersions
via The Hacker News
v3Tier C119d ago

Updated description to include the name 'BlueHammer', marked exploit as available, and noted that it is actively exploited.

descriptionexploitAvailableactivelyExploited
via Krebs on Security
v2Tier C120d ago

Updated severity to CRITICAL and noted that no exploit is available.

severity
via VulDB
v1120d ago

Initial creation