Three Windows zero-days are in the wild. One is patched. Here's what to do about the other two.

Three Windows zero-days are in the wild. One is patched. Here's what to do about the other two.

What happened

A security researcher going by "Chaotic Eclipse" dropped working exploit code for a Windows local privilege escalation flaw called BlueHammer on GitHub on April 3rd. No coordinated disclosure, no CVE assignment, no patch. The researcher was reportedly frustrated with how their vulnerability report was handled and decided to go public.

Then it got worse. Two more exploits followed: RedSun and UnDefend, both targeting Windows Defender's own processes to escalate a low-privilege user to SYSTEM-level access. Microsoft patched BlueHammer (now CVE-2026-33825) in the April 15 Patch Tuesday update, but RedSun and UnDefend remain unpatched as of today. And attackers aren't waiting around. Huntress confirmed this week that all three exploits are being used against live enterprise targets.

Why this one matters more than the usual Patch Tuesday noise

April's Patch Tuesday was already massive on its own: 167 flaws fixed, eight of them rated critical, plus an Adobe Reader zero-day that's been exploited since November 2025. That's a lot. But the BlueHammer saga is the one I keep coming back to, because it's not just a vulnerability story. It's a process failure story.

The exploits themselves are clever. BlueHammer abuses a timing flaw in Windows Defender's signature update workflow, chaining together Volume Shadow Copy, Cloud Files API callbacks, and opportunistic locks to pause Defender at exactly the right moment and read registry hives (SAM, SYSTEM, SECURITY) that are normally locked. No kernel exploit, no memory corruption, no shellcode. Just legitimate Windows features combined in the wrong order. The Cyderes Howler Cell team independently verified the full chain works on patched Windows 10 and 11 systems.

RedSun is arguably nastier. It tricks Defender's real-time engine into a detection-and-remediation cycle using an EICAR test file as bait, then exploits the remediation logic to overwrite system files and gain admin privileges. It works even after applying the April patches.

What makes this uncomfortable for development teams specifically: these exploits target Windows Defender, the thing most organizations assume is protecting their endpoints. If you're a team that builds and deploys on Windows, your dev machines, your CI runners, your staging servers, they're all in scope.

What this means for development teams

During our penetration testing work with gaming studios and enterprise clients, we've seen time and again that local privilege escalation is the step that turns a minor foothold into a full compromise. Someone clicks a phishing link, gets a limited shell, and then it's game over if LPE is easy. These three exploits make LPE very easy on unpatched Windows machines.

Here's the practical concern for dev teams: developer workstations are often the weakest link. They tend to have more software installed, more exceptions in security policies, more local admin access than they should. We've found this pattern repeatedly, whether we're testing travel platforms or enterprise SaaS deployments. The dev machine is how attackers get in, and privilege escalation is how they get to stay.

With two out of three exploits still unpatched, you can't just "apply the update and move on" this time.

What you should do right now

First, apply the April Patch Tuesday updates immediately if you haven't. That covers BlueHammer and the other 166 vulnerabilities, including the Adobe Reader zero-day and a critical Active Directory RCE (CVE-2026-33826). This isn't optional.

Second, for RedSun and UnDefend, you need compensating controls until Microsoft ships patches:

  • Hunt for the known indicators. Huntress reported that attackers are dropping binaries named FunnyApp.exe, RedSun.exe, and z.exe in user Pictures folders and two-letter subfolders inside Downloads. Scan for those. Set up alerts for unexpected executables in user profile directories.
  • Monitor for privilege escalation and SAM access. Any process that suddenly jumps from standard user to SYSTEM, or any unexpected access to the SAM database, should trigger an alert. If your EDR isn't catching this, you have a bigger problem.
  • Enforce least privilege aggressively. These exploits require local access. Every reduction in who can log in, what they can run, and what local admin rights they have makes exploitation harder. This is a good week to audit developer machine policies.
  • Check your CI/CD runners. If you're running Windows-based build agents, make sure they're not accessible from the public internet, not running with unnecessary privileges, and not storing credentials that could be harvested post-exploitation.

Third, don't forget the Adobe Reader zero-day. If your team receives PDFs, and every team does, update Reader and Acrobat. This one has been exploited since late 2025 and only just got a patch.

The bigger picture: coordinated disclosure is fraying

The researcher's frustration with the disclosure process isn't new, but it's becoming more common. When reporting vulnerabilities feels like shouting into a void, some researchers will go public out of spite. That's bad for everyone, but the response from affected vendors needs to be faster and more respectful of the people finding these bugs.

From our security work, we've been on both sides of this. We've reported findings to vendors who moved fast and took it seriously. We've also had reports sit in limbo for months. The MSRC process has drawn criticism before, and this incident, where the researcher explicitly said they warned what would happen, is a clear example of what breaks down when trust between researchers and vendors erodes.

For teams that depend on Windows infrastructure, this means you can't just trust that vulnerabilities will be quietly patched before they become your problem. You need detection and response capabilities that assume zero-days will happen, because they will keep happening.

Also worth watching this week

Beyond the Windows drama, Apache ActiveMQ CVE-2026-34197 is worth a look. A researcher used an AI assistant to find a remote code execution vulnerability that had been hiding in the codebase for 13 years. If you run ActiveMQ, patch it. And the Chaos malware variant now targeting misconfigured Linux cloud servers, which previously stuck to routers, is a reminder that every internet-facing service needs hardening, not just the ones you think attackers care about.

When we configure cloud infrastructure and set up DDoS protection for clients, the first step is always an honest inventory of what's actually exposed. Most teams are surprised by what they find.

Wrapping up

This week is a reminder that endpoint security isn't a set-and-forget exercise. Two unpatched privilege escalation zero-days are in active use, targeting the very tool (Windows Defender) that most organizations rely on for protection. The development teams we work with know this pattern: security isn't a product you buy, it's a process you maintain.

Patch what you can, hunt for what you can't patch, and tighten local access policies on your developer machines and build servers. If you're not sure where your Windows environment stands or want help running through the exposure from these zero-days, let's talk.

expert-analysispatch-tuesdaysecuritytech-newswindowszero-day