{"id":40092,"date":"2026-04-17T10:36:21","date_gmt":"2026-04-17T08:36:21","guid":{"rendered":"https:\/\/borncity.com\/win\/?p=40092"},"modified":"2026-04-17T10:37:04","modified_gmt":"2026-04-17T08:37:04","slug":"windows-defender-0-days-bluehammer-patched-and-redsun-unpatched","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2026\/04\/17\/windows-defender-0-days-bluehammer-patched-and-redsun-unpatched\/","title":{"rendered":"Windows Defender 0-days: BlueHammer (patched) and RedSun (unpatched)"},"content":{"rendered":"<p><img decoding=\"async\" style=\"margin: 0px 10px 0px 0px; display: inline; float: left;\" title=\"Windows\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" alt=\"Windows\" width=\"200\" align=\"left\" \/>There are several critical vulnerabilities in Microsoft Defender, that put Windows systems at risk. A security researcher has published an 0-day-exploit named <em>BlueHammer<\/em> on April 3, 2026, that has been patched on April 14, 2026. But there is still an unpatched vulnerability, where the security researcher has published the <em>RedSun<\/em> exploit. And ther is <em>UnDefend,<\/em> allowing to stop Windows Defender.<\/p>\n<p><!--more--><\/p>\n<h2>Controversy Over the MSRC Team's Incompetence<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg06.met.vgwort.de\/na\/63f8513204dc4d099acc6660c4a08040\" alt=\"\" width=\"1\" height=\"1\" \/>A security researcher with the alias Chaotic Eclipse constantly publishes zero-day exploits on GitHub, affecting Microsoft Defender shipped in Windows. The reason for each action is &#8211; in my opionion &#8211; to outline the internal\u00a0working methods of the Microsoft Security Response Team (MSRT). The team members have become so conditioned to processing security reports strictly by the book that security reports are often misclassified or incorrectly assessed.<\/p>\n<h2>The BlueHammer exploit<\/h2>\n<p>Some time ago, Chaotic Eclipse reported a vulnerability in the MSRT that affected Defender's behavior. As I understand it, he\u00a0 received a negative response. In response, Chaotic Eclipse made the information about the vulnerability public on X on April 3, 2026, and posted a proof of concept (PoC) for an exploit on GitHub.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-323463\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2026\/04\/BlueHammer.jpg\" sizes=\"auto, (max-width: 599px) 100vw, 599px\" srcset=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2026\/04\/BlueHammer.jpg 599w, https:\/\/borncity.com\/blog\/wp-content\/uploads\/2026\/04\/BlueHammer-300x263.jpg 300w\" alt=\"BlueHammer \" width=\"599\" height=\"525\" data-cmp-info=\"10\" \/><\/p>\n<p>The tweet above addresses the issue I described in my German blog post <a href=\"https:\/\/borncity.com\/blog\/2026\/04\/09\/bluehammer-windows-0-day-schwachstelle\/\" target=\"_blank\" rel=\"bookmark noopener\">BlueHammer: Windows 0-day-Schwachstelle<\/a> [use the build-in translator of the blog, to change the language].On April 14, 2026, Microsoft released a patch\u2014and I addressed this in a follow-up post titled <a href=\"https:\/\/borncity.com\/blog\/2026\/04\/16\/bluehammer-nachlese-defender-patch-vom-14-4-2026-und-analyse-von-fortra\/\" target=\"_blank\" rel=\"bookmark noopener\">BlueHammer-Nachlese: Defender-Patch vom 14.4.2026 und Analyse von Fortra<\/a> which also included an analysis by Fortra.<\/p>\n<h2>RedSun: Another Windows Defender 0-day<\/h2>\n<p>I came across information about another, as yet unpatched, vulnerability in Windows Defender via the <a href=\"https:\/\/xcancel.com\/weezerOSINT\/status\/2044707254977593839\" target=\"_blank\" rel=\"noopener\">tweet<\/a> below. The post warns that the Defender included with Windows has been \"compromised.\"<\/p>\n<p><a href=\"https:\/\/xcancel.com\/weezerOSINT\/status\/2044707254977593839\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-323801\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2026\/04\/Windows-Defender-RedSun01.jpg\" alt=\"Windows Defender 0-day RedSun01\" width=\"532\" height=\"677\" \/><\/a><\/p>\n<p>It says, there is a publicly known, unpatched exploit that grants any app on a Windows system full system administrator privileges. The attack vector is Microsoft Defender. Ransomware gangs could exploit this to encrypt the entire system and steal all stored passwords, browser sessions, and Discord tokens. This is reportedly possible even on a fully patched Windows 11 system with real-time protection enabled.<\/p>\n<p>The zero-day exploit exploits a race condition: If Microsoft Defender detects a suspicious file marked with a cloud tag, it attempts to \"repair\" it. This repair involves Defender copying the file back to its original location.<\/p>\n<p>The exploit now uses the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/ifs\/oplock-overview#:~:text=An%20oplock%20(opportunistic%20lock)%20is,client%20applications%20on%20local%20servers.\" target=\"_blank\" rel=\"noopener\">OPLOCK<\/a> technique and a junction to redirect this write operation to C:\\Windows\\System32. While Defender \"believes\" it is saving the files to a temporary folder, they are actually written to the C:\\Windows\\System32 folder. This way, attackers could trick Defender into delivering an infected file containing a payload directly to the System32 folder itself. These files can then be executed with system privileges. Chaotic Eclipse has published the <a href=\"https:\/\/github.com\/Nightmare-Eclipse\/RedSun\" target=\"_blank\" rel=\"noopener\">exploit on GitHub<\/a>.<\/p>\n<h2>UnDefend blocks Defender Updates<\/h2>\n<p>In addition to the aforementioned 0-day exploits BlueHammer (CVE-2026-33825) and RedSun, Chaotic Eclipse has also released the tool <a href=\"https:\/\/github.com\/Nightmare-Eclipse\/UnDefend\" target=\"_blank\" rel=\"noopener\">UnDefend<\/a> within the past 14 days. UnDefend is a repository published on GitHub containing a Windows Defender denial-of-service (DoS) tool. This tool can blog Defender signature updates &#8211; and in some condition it's able to stop Microsoft Defender operation complete. Details may be found at GitHub.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There are several critical vulnerabilities in Microsoft Defender, that put Windows systems at risk. A security researcher has published an 0-day-exploit named BlueHammer on April 3, 2026, that has been patched on April 14, 2026. But there is still an &hellip; <a href=\"https:\/\/borncity.com\/win\/2026\/04\/17\/windows-defender-0-days-bluehammer-patched-and-redsun-unpatched\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[773,47,69,194],"class_list":["post-40092","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-defender","tag-issue","tag-security","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/40092","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=40092"}],"version-history":[{"count":2,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/40092\/revisions"}],"predecessor-version":[{"id":40094,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/40092\/revisions\/40094"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=40092"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=40092"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=40092"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}