Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Security Patch Release ×3

BlueHammer Windows privilege escalation and Microsoft remediation

Updated 30.06.2026 11:53
Case score 59
Members 4 First seen 06.04.2026 22:19 Latest activity 30.06.2026 11:53

Overview

Public exploit code for **BlueHammer / CVE-2026-33825** turned a Windows local privilege-escalation flaw into an active zero-day risk. The issue can expose the **SAM** database and let a local attacker reach **SYSTEM** or elevated administrator access, although the available proof-of-concept was not reliable in every environment. Microsoft has since patched the flaw in the April 2026 updates, including the **Defender Antimalware Platform update 4.18.26050.3011**. CISA also added the CVE to the Known Exploited Vulnerabilities list and set a **May 7** deadline for federal civilian agencies.
Latest development Open development history 3 earlier developments Microsoft ships Patch Tuesday fix for CVE-2026-33825 Microsoft fixed CVE-2026-33825 as part of this month's Patch Tuesday security updates, closing a Microsoft Defender local privilege escalation flaw that could grant SYSTEM privileges on Windows 10, Windows 11, and Windows Server when Windows Defender is enabled.
  1. Earlier development

    Microsoft flags exploitation risk and hardening steps

    Microsoft assessed 19 newly disclosed vulnerabilities as more likely to be exploited, and researchers warned that CVE-2026-33825 could be chained with other exploits to expand initial access and gain system-level control on vulnerable endpoints. Microsoft said Defender instances with automatic updates were already protected, while organizations that do not use IKE should block UDP ports 500 and 4500 and required IKE deployments should restrict inbound traffic to known peer addresses.

  2. Earlier development

    Microsoft details zero-days and update guidance

    Microsoft identifies CVE-2026-32201 as a Microsoft SharePoint Server spoofing vulnerability exploited in attacks and CVE-2026-33825 as a Microsoft Defender elevation of privilege flaw that can grant SYSTEM privileges, while also fixing Microsoft Office remote code execution bugs that can be triggered through the preview pane or malicious documents and urging prompt Office updating.

  3. Earlier development

    Analyst confirms BlueHammer privilege escalation impact

    Security analyst Will Dormann confirmed that BlueHammer is a local privilege escalation in Windows that combines TOCTOU and path confusion, can expose the Security Account Manager (SAM) database with local-account password hashes, and may let a local attacker escalate to SYSTEM or elevated administrator privileges; testers also said it did not work reliably on Windows Server.

Signals

Impact signals
Exploitation
CVEs/products
Remediation
Threat context
Data exposure

Threat actor context

1 listed

Tooling context

4 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Windows BlueHammer local public exploit privilege-escalation flaw
Updated 06.04.2026 22:19 Lead Contribution 59
Exploit Public Exploit Data Type Passwords Data Status Publicly Available Patch No Patch

**BlueHammer** (**CVE-2026-33825**) is a **Microsoft Defender** local privilege-escalation vulnerability that Microsoft patched on **April 14** but that has since been abused in **zero-day** attacks and is now being exploited by **ransomware gangs**. The flaw can let a local attacker reach the **SAM database**, extract password hashes, escalate to **SYSTEM** privileges, and take over affected **Windows** systems. **CISA** added it to the **Known Exploited Vulnerabilities (KEV) Catalog** and has flagged it for active ransomware campaign abuse.

Security Patch Release Microsoft April 2026 Patch Tuesday security update (165 CVEs)
Updated 15.04.2026 00:22 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency High Patch Patch Available

**Microsoft** shipped **April 2026 Patch Tuesday** updates covering **165 CVEs**, including an **actively exploited zero-day** and a **publicly disclosed** flaw, creating immediate remediation pressure across Windows and related products. The bundle matters because multiple patched bugs can enable **remote code execution**, **elevation of privilege**, or **information disclosure**. Microsoft also said **19 vulnerabilities** are more likely to be exploited and need **high-priority attention**. The update spans **SharePoint Server**, **Defender**, **Windows IKE**, **Word**, and nearly **80 Edge/Chromium fixes**.

Security Patch Release Microsoft April 2026 Patch Tuesday security updates (167 flaws)
Updated 14.04.2026 20:41 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency High Patch Patch Available

Microsoft's **April 2026 Patch Tuesday** ships **security updates** for **167 flaws**, including **2 zero-days**, reducing exposure across widely used Microsoft software. The release also fixes **8 Critical vulnerabilities**, including **7 remote code execution** bugs and **1 denial of service** flaw. That scope makes the update bundle especially important for systems running **Microsoft Office**, **SharePoint Server**, and **Microsoft Defender**.

Security Patch Release Microsoft Defender BlueHammer (CVE-2026-33825) Patch Tuesday update
Updated 16.04.2026 23:19 Context
Patch Patch Available

**Microsoft** shipped a **Patch Tuesday** fix for **CVE-2026-33825**, a **Microsoft Defender** local-privilege-escalation flaw that can lead to **SYSTEM** access. The update narrows exposure on affected **Windows 10**, **Windows 11**, and **Windows Server** systems when Defender is enabled. It matters because a released exploit showed the issue was already actionable before the fix landed.