A tool designed to protect systems can also become an entry point for an attack. That is what happened with CVE-2026-33825, known as BlueHammer, a high-severity vulnerability in Microsoft Defender is already being exploited in real-world attacks.
The flaw allows an authenticated user to locally escalate privileges due to insufficiently granular access controls. Once exploited, it can provide access to the Security Account Manager (SAM)database, which contains password hashes for local accounts, potentially allowing attackers to obtain SYSTEM privileges and take control of the device.
The vulnerability was disclosed in early April by the security researcher known as Nightmare Eclipse, who also published a proof-of-concept exploit. Microsoft addressed the flaw through its April 2026 security update. Just days later, Huntress researchers identified evidence that the vulnerability was already being exploited as a zero-day in real-world attacks.
CISA added CVE-2026-33825 to its Known Exploited Vulnerabilities (KEV) catalog in April, signalling that active exploitation was taking place and reinforcing the priority of applying the available security updates. More recently, the agency updated the entry to indicate that the vulnerability was being used in ransomware campaigns..
The case highlights an issue that goes beyond simply applying a patch: fixing a vulnerability does not necessarily mean that an organisation was not compromised while it was exposed..
When a vulnerability enables privilege escalation, it can become part of a broader attack chain. An attacker may start with a compromised credential or access to an endpoint, exploit a vulnerability, escalate privileges and then attempt to move laterally across the infrastructure.
This is why vulnerability management needs to be supported by continuous visibility and monitoring. Knowing that a vulnerability exists is important. Knowing where it exists, whether it was exploited and what activity took place during the period of exposure is even more important.
Its inclusion in CISA's KEV catalog is a clear reminder that vulnerability prioritisation should not be based solely on a vulnerability's technical severity rating. Asset exposure, known exploitation and potential business impact should also influence the response.
Ransomware rarely starts when files are encrypted. Before that happens, an attacker may already have gained access, escalated privileges, stolen credentials, moved laterally and identified critical systems.
Protecting an infrastructure therefore requires more than keeping security tools up to date. Organisations need to combine vulnerability management, endpoint protection, identity management, monitoring, detection and incident response..
BlueHammer sends a clear message: a vulnerability can be patched, but risk is only truly reduced when an organisation can understand what happened before, during and after the vulnerability was fixed.
At ORBCOM, we believe cybersecurity must be approached as an integrated discipline: the right technology, effective implementation, continuous monitoring and the ability to respond.
Because security is not only about preventing an attacker from getting in.
It is also about detecting when they try — and acting before the impact reaches the business
CVE-2026-33825, known as BlueHammer, is a privilege escalation vulnerability in Microsoft Defender that can allow an authenticated user to gain elevated privileges on a vulnerable system.
BlueHammer is the name associated with CVE-2026-33825, a vulnerability in Microsoft Defender that can allow attackers to escalate privileges on affected systems.
According to CISA, CVE-2026-33825 is being exploited in ransomware campaigns. Organisations with affected systems should therefore confirm that the relevant security updates have been applied and check for any potential signs of exploitation.
No. Applying security patches reduces exposure to known vulnerabilities, but it does not eliminate the risk of ransomware. Protection should also include identity and privilege management, endpoint protection, monitoring, detection and incident response.
Sign up to our newsletter and keep up with the latest insights.
If you would like to get to know ORBCOM better and understand how our products, consulting services and outsourcing, fit your reality, speak to a specialist.