AI Briefing
KO

RedSun: Gaining SYSTEM Privileges on Win 11/10 and Server with April 2026 Update Applied

·2026.04.16 12:54

Key point

It's a PoC that exploits Windows Defender behavior to overwrite system files.

Details

The RedSun repository contains a PoC that exploits Windows Defender's cloud tag handling behavior.

When a cloud tag is attached to a malicious file, Defender writes it back into its original location, and this behavior is exploited to achieve system file overwriting and administrator privilege escalation.

The key points are as follows.

  • Target: Win 11/10 and Server
  • Timing: April 2026 Update environment
  • Attack method: privilege escalation using Defender's file rewrite behavior
  • Repository composition: C++ PoC including RedSun.cpp and explanatory resources

The author explains that this behavior is supposed to remove the malicious file, but instead actually rewrites the file, which is what makes the vulnerability possible.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.