RedSun PoC Uses Windows Defender Tag to Overwrite Files and Escalate Privileges

The RedSun proof‑of‑concept demonstrates that when Windows Defender detects a malicious file marked with a cloud‑based detection tag, it may rewrite the file to its original location instead of isolating it, allowing an attacker to replace system files and obtain administrator privileges.

Black & White Path
Black & White Path
Black & White Path
RedSun PoC Uses Windows Defender Tag to Overwrite Files and Escalate Privileges

The RedSun project reveals a zero‑day local privilege escalation (LPE) vulnerability in Windows Defender.

When Defender scans a file flagged by its cloud‑based detection service, it can rewrite the detected file back to its original path instead of moving it to quarantine.

The PoC leverages this rewrite behavior as a file‑overwrite primitive: by supplying a malicious payload with the cloud tag, the attacker can replace critical system files, which, when loaded, grant administrator rights.

This technique demonstrates how the Defender component can be abused to achieve privilege escalation without requiring a separate exploit chain.

The full proof‑of‑concept and details are available at the GitHub repository: https://github.com/Nightmare-Eclipse/RedSun.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

Security ResearchWindows DefenderZero-DayLocal Privilege EscalationRedSun
Black & White Path
Written by

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.