Microsoft Defender Three Zero-Days Privilege Escalation | MSSP Advisory
CriticalCredible Report
DateApril 21, 2026
📋Executive Summary
Threat actors are actively exploiting three zero-day vulnerabilities in Microsoft Defender codenamed BlueHammer, RedSun, and UnDefend that allow privilege escalation on compromised systems. Two of these flaws remain unpatched according to Huntress research. The exploits target Windows Defender's core protection mechanisms to gain elevated system access.
⚠️Why It Matters for MSSPs
Your client endpoints running Windows Defender are exposed to privilege escalation attacks through unpatched zero-days that Microsoft has not yet addressed. If attackers gain initial access to your RMM agents or client networks, these Defender exploits hand them administrative privileges to move laterally and disable security controls.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.