CVE-2026-33825

9.5 CISA KEV

Microsoft · Defender

A local privilege escalation vulnerability in the Microsoft Defender Antimalware Platform allows authorized attackers to gain SYSTEM level access via a race condition.

Executive summary

A critical local privilege escalation vulnerability in Microsoft Defender, known as BlueHammer, allows attackers to gain SYSTEM level access and is currently being exploited in the wild.

Vulnerability

This vulnerability, identified as a time-of-check to time-of-use (TOCTOU) race condition, allows an attacker who already has local access to elevate their privileges to SYSTEM. The flaw stems from insufficient granularity of access control within the Defender platform.

Business impact

With a CVSS score of 9.5, this vulnerability is extremely dangerous because it grants an attacker the highest level of system privileges. By disabling endpoint protection, attackers can bypass security controls to deploy ransomware or maintain long-term persistence. The active exploitation by ransomware groups underscores the necessity of treating this as a high-urgency remediation task.

Remediation

Immediate Action: Apply the security update to version 4.18.26030.3011 (KB4052623) via Windows Update or the Microsoft Update Catalog.

Proactive Monitoring: Monitor endpoint logs for suspicious privilege escalation attempts or attempts to disable the Microsoft Defender service.

Compensating Controls: Implement strict Application Control policies to limit the execution of unauthorized binaries that could be used to trigger the race condition.

Exploitation status

Public Exploit Available: Yes (public GitHub PoCs exist)

Analyst recommendation

The risk of this privilege escalation is compounded by its use in active ransomware campaigns. IT and security teams must ensure that all systems receive the update to version 4.18.26030.3011 immediately to prevent attackers from gaining SYSTEM-level control over protected endpoints.

More Microsoft CVEs

Sources