tag
Privileged-File-Write
CVE-2026-33825
binary
HIGH 7.8
KEV
Ransomware
RedSun Privileged File Write (CVE-2026-33825)
RedSun documents a local privilege-escalation technique where Defender's handling of a cloud-tagged malicious file can be abused as a privileged file write primitive. The PoC orchestrates file operations so the antimalware rewrite path lands on a high-value…
Patched
2026-05-15