CVE-2026-33825
9.5 CISA KEVMicrosoft · Defender
A local privilege escalation vulnerability in the Microsoft Defender Antimalware Platform allows authorized attackers to gain SYSTEM level access via a race condition.
Executive summary
A critical local privilege escalation vulnerability in Microsoft Defender, known as BlueHammer, allows attackers to gain SYSTEM level access and is currently being exploited in the wild.
Vulnerability
This vulnerability, identified as a time-of-check to time-of-use (TOCTOU) race condition, allows an attacker who already has local access to elevate their privileges to SYSTEM. The flaw stems from insufficient granularity of access control within the Defender platform.
Business impact
With a CVSS score of 9.5, this vulnerability is extremely dangerous because it grants an attacker the highest level of system privileges. By disabling endpoint protection, attackers can bypass security controls to deploy ransomware or maintain long-term persistence. The active exploitation by ransomware groups underscores the necessity of treating this as a high-urgency remediation task.
Remediation
Immediate Action: Apply the security update to version 4.18.26030.3011 (KB4052623) via Windows Update or the Microsoft Update Catalog.
Proactive Monitoring: Monitor endpoint logs for suspicious privilege escalation attempts or attempts to disable the Microsoft Defender service.
Compensating Controls: Implement strict Application Control policies to limit the execution of unauthorized binaries that could be used to trigger the race condition.
Exploitation status
Public Exploit Available: Yes (public GitHub PoCs exist)
Analyst recommendation
The risk of this privilege escalation is compounded by its use in active ransomware campaigns. IT and security teams must ensure that all systems receive the update to version 4.18.26030.3011 immediately to prevent attackers from gaining SYSTEM-level control over protected endpoints.
More Microsoft CVEs
Sources
- Microsoft Defender Elevation of Privilege Vulnerability Vendor advisory