Vulnerability in Microsoft Defender Now Linked to Ransomware Attacks

Vulnerability in Microsoft Defender Now Linked to Ransomware Attacks

A vulnerability in Microsoft Defender, the antivirus platform built into Windows, is now reportedly being used in ransomware attacks, according to updates tracked by CISA and highlighted by GreyNoise.

The vulnerability, tracked as CVE-2026-33825, allows an attacker who already has limited access to a system to elevate privileges to SYSTEM, effectively gaining full control over the affected machine.

At first glance, the vulnerability may not have looked especially alarming compared to internet-facing remote code execution flaws. The issue requires local access and carries a CVSS score of 7.8. However, the operational risk around the vulnerability evolved quickly over time.

That evolution is exactly what makes this case interesting.

From Proof-of-Concept to Ransomware Activity

Researcher “BlueHammer” publicly disclosed the vulnerability in early April, together with proof-of-concept exploit code. Microsoft released security updates on April 14 and already warned at the time that exploitation was considered “more likely.”

Shortly afterward:

  • The vulnerability was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog
  • Active exploitation was confirmed
  • The vulnerability was later associated with ransomware activity

According to GreyNoise, this last step often happens quietly.

The Problem of “Silent” KEV Updates

GreyNoise recently highlighted how CISA sometimes updates existing KEV entries with new ransomware-related intelligence without making separate announcements.

Specifically, the field:

knownRansomwareCampaignUse

can silently change from:

Unknown → Known

Operationally, that is a meaningful shift in risk.

A vulnerability that may initially appear to be “just” a privilege escalation issue can suddenly become part of active ransomware playbooks weeks or months later.

According to GreyNoise, 59 vulnerabilities silently received ransomware-related updates in 2025 alone.

That highlights an important challenge for defenders: threat intelligence is not static.

Why CVE-2026-33825 Matters

Microsoft describes the vulnerability as an Elevation of Privilege issue caused by insufficient granularity of access control in Microsoft Defender.

A successful attacker can obtain:

  • SYSTEM privileges
  • Full access to affected systems
  • The ability to disable protections or deploy additional payloads

The vulnerability affects Microsoft Defender Antimalware Platform versions up to:

4.18.26020.6

and was fixed in:

4.18.26030.3011

Importantly, Microsoft Defender updates are typically deployed automatically. However, organizations should still verify that update distribution is functioning correctly across their environments.

Detection and Verification

Microsoft recommends verifying that the latest Defender platform updates and malware definitions are installed.

Administrators can verify this by:

  1. Opening Windows Security
  2. Navigating to Virus & threat protection and then Protection updates
  3. Selecting Check for updates
  4. Reviewing the installed antimalware platform version under Settings and About

Organizations should also investigate:

  • Systems with outdated Defender platform versions
  • Unexpected privilege escalation events
  • Suspicious Defender service activity
  • Indicators of ransomware deployment
  • Systems where update distribution may have failed

One particularly useful Microsoft clarification is that vulnerability scanners may still flag the issue even when Defender itself has been disabled. This happens because the affected Defender binaries may still exist on disk, even if the product is inactive.

Why This Matters

CVE-2026-33825 shows how quickly the operational risk around a vulnerability can change.

What initially appeared to be a local privilege escalation vulnerability later gained public exploit code, active exploitation, KEV inclusion, and reported ransomware usage.

That evolution significantly changes remediation priority.

How BaseFortify Fits In

Our CVE report for CVE-2026-33825 helps track the broader operational context around the vulnerability, including exploitability indicators, associated products, and evolving threat intelligence.

Readers can consult the report here:

https://basefortify.eu/cve_reports/2026/04/cve-2026-33825.html

Users can also register for a free BaseFortify account at:

https://basefortify.eu/register

As this case demonstrates, vulnerabilities do not remain static after disclosure. Monitoring how exploitation activity evolves can be just as important as the original advisory itself.

Sources