Summary

CISA has confirmed that ransomware gangs are actively exploiting CVE-2026-33825, a high-severity privilege escalation vulnerability in Microsoft Defender dubbed “BlueHammer.” The flaw, which was initially leaked by a security researcher, allows authorized local attackers to escalate privileges on affected Windows systems.

The vulnerability was already being abused in targeted zero-day attacks before the CISA advisory, and its addition to the Known Exploited Vulnerabilities (KEV) catalog on June 30 means federal agencies face mandatory patching deadlines. Multiple ransomware affiliates have incorporated BlueHammer into their post-compromise playbooks, using it to escalate from initial access to SYSTEM-level privileges before deploying their payloads.

The irony is not lost on anyone: the security product meant to protect Windows endpoints is now the attack surface. Microsoft patched the flaw in its June Patch Tuesday cycle (which addressed a record 208 CVEs), but the confirmation of active ransomware exploitation underscores the urgency for organizations that haven’t applied the update.

Sources

Commentary

Security tools becoming attack vectors is one of the most uncomfortable trends in modern cybersecurity, and BlueHammer is a textbook case. When your endpoint protection is the privilege escalation vector, the defender’s advantage evaporates. Ransomware operators are well aware that Defender is ubiquitous across enterprise Windows environments — it’s the largest homogeneous attack surface they could ask for.

If you’re running any unpatched Windows systems from the June cycle, treat this as a fire drill. The record-breaking 208 CVEs in that Patch Tuesday already made prioritization hard, but BlueHammer just jumped to the top of the list.

By Allan