<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Frustrated Researcher Leaks Windows Zero-Day Exploit After Microsoft Response Issues

Security researcher releases BlueHammer exploit code, highlighting issues with Microsoft's vulnerability disclosure process.
Content Team

A security researcher using the alias "Chaotic Eclipse" publicly released exploit code for an unpatched Windows zero-day vulnerability called "BlueHammer" on April 2, citing frustration with Microsoft's Security Response Center. The flaw combines a race condition and path confusion in Windows Defender's update system, potentially allowing local attackers to access password hashes and gain administrator rights.

The exploit currently works on desktop systems but not Windows Server. Security experts warn that skilled threat actors could quickly weaponize the proof-of-concept code, with ransomware groups typically deploying such exploits within days of release.

This incident highlights ongoing tensions between security researchers and Microsoft's vulnerability disclosure process, which critics have long called frustrating and opaque despite the company's 2023 promises to improve transparency.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo