A zero-day privilege escalation vulnerability named BlueHammer in Windows Defender was publicly disclosed with full working exploit source code, affecting Windows 10/11 and Windows Server. The vulnerability, discovered by a researcher operating under the alias Chaotic Eclipse, enables escalation from low-privileged accounts to system-level access. Microsoft has not yet issued a patch or CVE.
Safety
Windows Defender is being used to hack Windows
BlueHammer, an unpatched privilege escalation zero-day in Windows Defender, is being actively exploited with publicly released proof-of-concept code to escalate from user to system-level access on Windows 10/11 and Server.
Saturday, April 11, 2026 12:00 PM UTC2 MIN READSOURCE: LobstersBY sys://pipeline
Tags
safety