Summary
Microsoft Defender Antimalware Platform has a local elevation-of-privilege flaw in its signature and update workflow. A low-privilege local attacker can abuse a race or TOCTOU condition to steer privileged Defender file handling toward attacker-influenced paths and expose sensitive system data. Successful exploitation can raise the attacker to SYSTEM and fully compromise the endpoint.
Why Planned Fix?
5/6Exploitation Details
Gain SYSTEM-level privileges on the local machine
Full System CompromiseAffected Software
| Product | Affected Versions |
|---|---|
| Microsoft Defender Antimalware Platform | < 4.18.26030.3011 |
Microsoft Defender Antimalware Platform is the built-in Windows antivirus and antimalware engine that scans files, applies signatures, and enforces endpoint protection on Windows devices.
Affected ComponentDefender antimalware platform signature/update workflow and local access-control checks.
Defender antimalware platform signature/update workflow and local access-control checks.
Not available
Not available
Upgrade Microsoft Defender Antimalware Platform to version 4.18.26030.3011 or later through Microsoft security updates and platform updates.
Upgrade Microsoft Defender Antimalware Platform to version 4.18.26030.3011 or later through Microsoft security updates and platform updates.
Probability of exploitation in the next 30 days
Worse than 91% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (1)
- •cpe:2.3:a:microsoft:defender_antimalware_platform:*:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| msrc.microsoft.com | Security Update Guide - CVE-2026-33825 |
| nvd.nist.gov | CVE-2026-33825 Detail |
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
| www.huntress.com | Nightmare-Eclipse Tooling Seen in Real-World Intrusion |
| www.tenable.com | CVE-2026-33825 |
| www.rapid7.com | Patch Tuesday - April 2026 |
| github.com | Nightmare-Eclipse/BlueHammer |
| github.com | Nightmare-Eclipse/RedSun |
Priority History
Initial analysis
Elevated — new exploitation evidence confirmed