BlueHammer Windows privilege escalation and Microsoft remediation
Case score 59
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 59
- Main story score
- 59
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 3
- Vulnerability Public exploit release defines the Windows local privilege-escalation risk and the zero-day status. main
- Security Patch Release Specific Defender Patch Tuesday fix for CVE-2026-33825 and the affected Windows versions. context
- Security Patch Release Microsoft April 2026 Patch Tuesday context showing the same CVE was patched in a broader update bundle. context
- Security Patch Release Broader Microsoft April 2026 patch context for the same Defender CVE and adjacent Windows remediation guidance. context
Overview
Latest development Open development history Microsoft ships Patch Tuesday fix for CVE-2026-33825 Microsoft fixed CVE-2026-33825 as part of this month's Patch Tuesday security updates, closing a Microsoft Defender local privilege escalation flaw that could grant SYSTEM privileges on Windows 10, Windows 11, and Windows Server when Windows Defender is enabled.
-
Microsoft flags exploitation risk and hardening steps
Microsoft assessed 19 newly disclosed vulnerabilities as more likely to be exploited, and researchers warned that CVE-2026-33825 could be chained with other exploits to expand initial access and gain system-level control on vulnerable endpoints. Microsoft said Defender instances with automatic updates were already protected, while organizations that do not use IKE should block UDP ports 500 and 4500 and required IKE deployments should restrict inbound traffic to known peer addresses.
-
Microsoft details zero-days and update guidance
Microsoft identifies CVE-2026-32201 as a Microsoft SharePoint Server spoofing vulnerability exploited in attacks and CVE-2026-33825 as a Microsoft Defender elevation of privilege flaw that can grant SYSTEM privileges, while also fixing Microsoft Office remote code execution bugs that can be triggered through the preview pane or malicious documents and urging prompt Office updating.
-
Analyst confirms BlueHammer privilege escalation impact
Security analyst Will Dormann confirmed that BlueHammer is a local privilege escalation in Windows that combines TOCTOU and path confusion, can expose the Security Account Manager (SAM) database with local-account password hashes, and may let a local attacker escalate to SYSTEM or elevated administrator privileges; testers also said it did not work reliably on Windows Server.