‘They mopped the floor with me and pulled every childish game they could’: Disgruntled researcher releases second major Windows zero-day – claims Microsoft ‘wanted to ruin my life and they did’


  • Researcher “Chaotic Eclipse” reveals new Microsoft Defender zero-day dubbed RedSun
  • Flaw enables local privilege escalation to SYSTEM by abusing Defender’s file rewrite behavior
  • Coming days after BlueHammer release; Microsoft says it is investigating and supporting coordinated disclosure

The same disgruntled researcher who recently uncovered a zero-day vulnerability in Windows has now done it again, this time targeting Microsoft Defender, the operating system’s native antivirus solution.

A researcher with the alias “Chaotic Eclipse” has published a proof-of-concept (PoC) exploit for a vulnerability they named “RedSun”. It is a local privilege escalation flaw that allows malicious actors SYSTEM privileges in the latest versions of Windows 10, Windows 11, and Windows Server, with Windows Defender enabled.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top