‘They mopped the floor with me and took out every childish game they could’: Disgruntled researcher launches second major Windows Zero Day – claims Microsoft ‘was going to ruin my life, and they did’


  • “Chaotic Eclipse” researcher reveals new Microsoft Defender Zero Day called RedSun
  • Flaw allows local privilege escalation to SYSTEM by abusing Defender’s file rewrite behavior
  • Arriving a few days after the release of BlueHammer; Microsoft says it is investigating and supporting coordinated disclosure

The same disgruntled researcher who recently revealed a zero-day vulnerability in Windows is at it again, this time targeting Microsoft Defender, the operating system’s native antivirus solution.

A researcher going by the pseudonym “Chaotic Eclipse” has published a proof-of-concept (PoC) exploit for a vulnerability he named “RedSun.” This is a local privilege escalation vulnerability that grants malicious actors SYSTEM privileges in the latest versions of Windows 10, Windows 11, and Windows Server, with Windows Defender enabled.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top