CVE-2026-33825
CISA KEVAs of 2026-04-14, CVE-2026-33825 is a CVSS 7.8 (HIGH-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 7.1%. Threadlinqs Intelligence tracks 6 threats exploiting it.
Last updated: 2026-04-14
A TOCTOU race condition in the Microsoft Defender Antimalware Platform update orchestrator allows a local low-privileged user to write an arbitrary file as SYSTEM via a symbolic-link hijack of the platform update staging directory. Proof-of-concept code was published to GitHub prior to Microsoft's advisory. No in-the-wild exploitation confirmed at release time, but the bug is trivial to weaponize and expected to appear in commodity post-exploitation toolkits within days.
CVSS v3 vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-367, CWE-59
Exploitation status
CISA KEV-listed (known exploited)
Threats tracking this CVE
- RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) Patched — HIGH
- Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited In-The-Wild, CVE-2026-33825 Defender EoP Public PoC, CVE-2026-33824 IKE RCE CVSS 9.8, CVE-2026-33827 TCP/IP Wormable RCE) — CRITICAL
- Windows Defender Zero-Days (BlueHammer/RedSun/UnDefend) — Leaked Nightmare-Eclipse Exploits Weaponized In-The-Wild for SYSTEM LPE (CVE-2026-33825) — CRITICAL
- BlueHammer & RedSun: Windows Defender CVE-2026-33825 Zero-Day Remote Code Execution — CRITICAL
- CVE-2026-33825: Microsoft Defender Local Privilege Escalation via BlueHammer TOCTOU Race Condition — HIGH
- Microsoft April 2026 Patch Tuesday — 167 Flaws, 2 Zero-Days (SharePoint Spoofing CVE-2026-32201 + Defender EoP CVE-2026-33825) — CRITICAL
References
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.