RedSun: System user access on Win 11/10 and Server with the April 2026 Update
1–10 of 67 posts
Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#2Looks like that's exactly what they did though?
Or maybe they just meant that they don't usually explain how it works?
Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#3Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#4> normally I would just drop the PoC code and let people figure it out Looks like that's exactly what they did though? Or maybe they just meant that they don't usually explain how it works?
Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#5However, I don't know what I'm talking about so take it with a grain of salt!
Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#6Doesn't Linux have one of these CVEs...each week?
Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#7I wonder why Windows Defender has the privilege to alter the system files. Read them for analysis? Sure! Reset (as in, call some windows API to have it replaced with the original), why not? But being able to write sounds like a bad idea. However, I don't know what I'm talking about so take it with a grain of salt!
Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#8I wonder why Windows Defender has the privilege to alter the system files. Read them for analysis? Sure! Reset (as in, call some windows API to have it replaced with the original), why not? But being able to write sounds like a bad idea. However, I don't know what I'm talking about so take it with a grain of salt!
Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#9I wonder why Windows Defender has the privilege to alter the system files. Read them for analysis? Sure! Reset (as in, call some windows API to have it replaced with the original), why not? But being able to write sounds like a bad idea. However, I don't know what I'm talking about so take it with a grain of salt!
AV had traditionally run as SYSTEM on Windows (and, in the past, often had kernel mode drivers too). I've always thought it was a terrible idea. It opens up exciting new attack surfaces. Kaspersky and McAfee both had privilege escalation vulnerabilities that I can recall. There have been a ton in multiple products over the years.
If malware exploits a privilege escalation vuln, what's the AV going to do about it when it's reduced to the software equivalent of a UK police officer? Observe and report? Stop or I'll say "stop" again?
AV requires great power, which requires great responsibility. The second part is what often eludes AV developers.
Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update
#10Earlier quoted context omitted.
AV had traditionally run as SYSTEM on Windows (and, in the past, often had kernel mode drivers too). I've always thought it was a terrible idea. It opens up exciting new attack surfaces. Kaspersky and McAfee both had privilege escalation vulnerabilities that I can recall. There have been a ton in multiple products over the years.
They kind of have to, though. If malware exploits a privilege escalation vuln, what's the AV going to do about it when it's reduced to the software equivalent of a UK police officer? Observe and report? Stop or I'll say "stop" again? AV requires great power, which requires great responsibility. The second part is what often eludes AV developers.