


Perceptive Security
SOC/SIEM Consultancy

New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges
Published:
16 april 2026 om 20:19:31
Alert date:
16 april 2026 om 21:01:18
Source:
bleepingcomputer.com
Zero-Day Vulnerabilities, Security Tools, Operating Systems
Cybersecurity researcher 'Chaotic Eclipse' has published a proof-of-concept exploit for a second Microsoft Defender zero-day vulnerability dubbed 'RedSun' within two weeks. The exploit grants SYSTEM privileges on affected systems. This disclosure appears to be in protest of Microsoft's handling of cybersecurity research and researcher relations. The vulnerability represents a significant privilege escalation flaw in Microsoft's primary endpoint security solution. This is the second zero-day disclosed by the same researcher in a short timeframe, indicating ongoing tensions between security researchers and Microsoft's vulnerability disclosure process.
Technical details
Mitigation steps:
Affected products:
Microsoft Defender
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
