Back to updates
New releaseAug 20, 2026

CVE-2026-41091-PoC-Exploit Full-PoCv2

Local privilege escalation exploit for CVE-2026-41091 targeting Microsoft Defender. Uses Cloud Files API and NTFS junction redirection to gain NT AUTHORITY\SYSTEM from a low-privileged user. Includes full PoC and educational algorithm demonstration.

Share

SolarFlare

β˜€οΈ CVE-2026-41091 - RedSun (SolarFlare) - Microsoft Defender LPE Exploit

C++ Windows License CVSS CISA KEV

Microsoft Defender Link Following Vulnerability - Local Privilege Escalation to NT AUTHORITY\SYSTEM

The vulnerability is known as "RedSun" 🎯, "SolarFlare" is the name I gave to my exploit. βœ…

πŸ“Œ Overview

This repository contains a full working Proof of Concept (PoC) exploit for CVE-2026-41091, a critical local privilege escalation vulnerability in Microsoft Defender (Microsoft Malware Protection Engine). By exploiting improper link resolution (CWE-59), an authenticated low-privileged attacker can gain NT AUTHORITY\SYSTEM privileges.

The vulnerability, also known as "RedSun" or "SolarFlare", allows attackers to trick Microsoft Defender into writing arbitrary files to protected system locations with SYSTEM privileges using Cloud Files API (CfAPI) and NTFS junction points.

Note: This repository includes two versions:

  • basic_poc.cpp - Simplified algorithm demonstration (educational)
  • full_poc.cpp - Complete working exploit with all features

πŸ”₯ Key Features

CategoryFeatures
Exploitationβœ… Local Privilege Escalation to SYSTEM
βœ… Cloud Files API (CfAPI) Integration
βœ… Cloud Placeholder Creation
βœ… NTFS Junction Redirection
Techniquesβœ… Batch Oplock Abuse
βœ… VSS Snapshot Detection
βœ… EICAR Trigger
βœ… COM Service Activation
Targetβœ… Microsoft Defender < 1.1.26040.8
βœ… Windows 10/11
βœ… Windows Server 2019/2022
Usabilityβœ… Detailed Logging
βœ… Error Handling
βœ… Random Directory Names
βœ… Automatic Cleanup

🎯 Vulnerability Details

AttributeValue
CVE IDCVE-2026-41091
CVSS Score7.8 (High)
CVSS VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLocal
Privileges RequiredLow
User InteractionNone
ImpactSYSTEM-level code execution
CISA KEVβœ… Yes (actively exploited in the wild)
Patch AvailableMicrosoft Malware Protection Engine 1.1.26040.8

πŸ“¦ Affected Products

ProductAffected VersionsFixed Versions
Microsoft Malware Protection Engine< 1.1.26040.81.1.26040.8+
Microsoft Defender Antimalware Platform< 4.18.26040.74.18.26040.7+

πŸ”¬ Exploit Chain

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ SOLARFLARE EXPLOIT CHAIN                                                    β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚                                                                              β”‚
β”‚ 1. Create Working Directory                                                 β”‚
β”‚    └─> %TEMP%\SF-XXXX\                                                      β”‚
β”‚                                                                              β”‚
β”‚ 2. Trigger Defender with EICAR                                              β”‚
β”‚    └─> Write reversed EICAR to bait file                                    β”‚
β”‚                                                                              β”‚
β”‚ 3. Wait for VSS Snapshot                                                    β”‚
β”‚    └─> Detect Volume Shadow Copy creation                                   β”‚
β”‚                                                                              β”‚
β”‚ 4. Create First Batch Oplock                                                β”‚
β”‚    └─> FSCTL_REQUEST_BATCH_OPLOCK on bait file                              β”‚
β”‚                                                                              β”‚
β”‚ 5. Wait for Oplock Break                                                    β”‚
β”‚    └─> Acquire exclusive access                                             β”‚
β”‚                                                                              β”‚
β”‚ 6. Rename Directory                                                         β”‚
β”‚    └─> Move original directory to .tmp                                      β”‚
β”‚                                                                              β”‚
β”‚ 7. Register Cloud Sync Root                                                 β”‚
β”‚    └─> CfRegisterSyncRoot with Cloud Files API                              β”‚
β”‚                                                                              β”‚
β”‚ 8. Create Cloud Placeholder                                                 β”‚
β”‚    └─> CfCreatePlaceholders for bait file                                   β”‚
β”‚                                                                              β”‚
β”‚ 9. Create Second Batch Oplock                                               β”‚
β”‚    └─> FSCTL_REQUEST_BATCH_OPLOCK on cloud placeholder                      β”‚
β”‚                                                                              β”‚
β”‚ 10. Wait for Second Oplock Break                                            β”‚
β”‚     └─> Acquire exclusive access                                            β”‚
β”‚                                                                              β”‚
β”‚ 11. Rename Cloud Directory                                                  β”‚
β”‚     └─> Move cloud directory to .cloud.tmp                                  β”‚
β”‚                                                                              β”‚
β”‚ 12. Create NTFS Junction to System32                                        β”‚
β”‚     └─> Redirect to C:\Windows\System32                                     β”‚
β”‚                                                                              β”‚
β”‚ 13. Copy Payload to System32                                                β”‚
β”‚     └─> Copy bait file to System32 as TieringEngineService.exe              β”‚
β”‚                                                                              β”‚
β”‚ 14. Activate Service as SYSTEM                                              β”‚
β”‚     └─> CoCreateInstance(StorageTiersManagement)                            β”‚
β”‚                                                                              β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ“¦ Installation

Prerequisites

  • Windows 10/11 or Windows Server 2019/2022
  • Visual Studio 2019/2022 with C++ tools
  • Administrative privileges (for execution)

Build

# Clone the repository
git clone https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit
cd CVE-2026-41091-PoC-Exploit

# Build using Visual Studio Developer Command Prompt
cl.exe /EHsc /std:c++17 full_poc.cpp /link cfapi.lib ntdll.lib

# Or build basic version
cl.exe /EHsc /std:c++17 basic_poc.cpp /link ntdll.lib

πŸ› οΈ Usage

Full Exploit (SYSTEM Privilege Escalation)

full_poc.exe

Basic Algorithm Demonstration

basic_poc.exe

πŸ“‹ Example Output

Full Exploit Output

CVE-2026-41091 SolarFlare PoC
===============================
     by @tc4dy | CVSS 7.8
===============================

Categories