“They mopped the floor with me and took out all the children’s games they could”: Disgruntled researcher launches second big Windows zero-day; claims Microsoft would “ruin my life, and they did”



  • “Chaotic Eclipse” researcher reveals new zero-day Microsoft Defender called RedSun
  • Flaw allows escalation of local privileges to SYSTEM by abusing Defender’s file rewrite behavior
  • It arrives days after the launch of BlueHammer; Microsoft says it investigates and supports coordinated disclosure

The same disgruntled researcher who recently revealed a zero-day vulnerability in Windows has done it again, this time targeting Microsoft Defender, the operating system’s native antivirus solution.

A researcher with the alias “Chaotic Eclipse” published a proof-of-concept (PoC) exploit for a vulnerability he called “RedSun.” It is a local privilege escalation flaw that allows malicious actors SYSTEM privileges on the latest versions of Windows 10, Windows 11, and Windows Server, with Windows Defender enabled.



Leave a Comment

Your email address will not be published. Required fields are marked *