216.73.216.6

Zero-Day Local Privilege Escalation Exploit

· Published 21/04/2026 10:48 · Modified 21/04/2026 09:27

Export JSON

Essential information

Published
21/04/2026 10:48
Modified
21/04/2026 09:27
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
filesystem manipulation microsoft defender privilege escalation redsun redsun.exe system access tieringengineservice windows zero-day
Tags
2026-04-21 filesystem manipulation microsoft defender privilege-escalation redsun redsun.exe system access tieringengineservice windows zero-day
Related entities
1 indicators, 1 observables, 17 techniques (mitre), 1 malware

Description

is a publicly available proof-of-concept exploit targeting a vulnerability in that enables local from standard user to SYSTEM-level access on systems. The exploit leverages flawed Defender remediation logic for cloud-tagged malicious files, combined with filesystem primitives to redirect high-privilege file operations. This allows attackers to overwrite protected system locations such as C:\\System32 with malicious binaries, achieving arbitrary code execution as SYSTEM without requiring administrator privileges or kernel exploits. The technique is reliable, actively weaponized, and potentially unpatched in some environments, making it a critical post-exploitation tool for persistence, lateral movement, and defense evasion. Organizations should implement rapid patching, enforce least privilege principles, and deploy behavior-based detection for suspicious Defender-related file operations and attempts.

External references