
CVE-2026-41091 RedSun | Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM π₯ via Cloud Files API + NTFS junction trickery. Forces Defender to write malicious payloads to System32 with SYSTEM rights. β οΈ Actively exploited in wild. CVSS 7.8. Patch: Defender Engine 1.1.26040.8. π‘οΈ Educational PoC only.

Microsoft Defender Link Following Vulnerability - Local Privilege Escalation to NT AUTHORITY\SYSTEM
This repository contains a full working Proof of Concept (PoC) exploit for CVE-2026-41091, a critical local privilege escalation vulnerability in Microsoft Defender (Microsoft Malware Protection Engine). By exploiting improper link resolution (CWE-59), an authenticated low-privileged attacker can gain NT AUTHORITY\SYSTEM privileges.
The vulnerability, also known as "RedSun" or "SolarFlare", allows attackers to trick Microsoft Defender into writing arbitrary files to protected system locations with SYSTEM privileges using Cloud Files API (CfAPI) and NTFS junction points.
Note: This repository includes two versions:
basic_poc.cpp- Simplified algorithm demonstration (educational)full_poc.cpp- Complete working exploit with all features
| Category | Features |
|---|---|
| Exploitation | β
Local Privilege Escalation to SYSTEM β Cloud Files API (CfAPI) Integration β Cloud Placeholder Creation β NTFS Junction Redirection |
| Techniques | β
Batch Oplock Abuse β VSS Snapshot Detection β EICAR Trigger β COM Service Activation |
| Target | β
Microsoft Defender < 1.1.26040.8 β Windows 10/11 β Windows Server 2019/2022 |
| Usability | β
Detailed Logging β Error Handling β Random Directory Names β Automatic Cleanup |
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-41091 |
| CVSS Score | 7.8 (High) |
| CVSS Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Local |
| Privileges Required | Low |
| User Interaction | None |
| Impact | SYSTEM-level code execution |
| CISA KEV | β Yes (actively exploited in the wild) |
| Patch Available | Microsoft Malware Protection Engine 1.1.26040.8 |
| Product | Affected Versions | Fixed Versions |
|---|---|---|
| Microsoft Malware Protection Engine | < 1.1.26040.8 | 1.1.26040.8+ |
| Microsoft Defender Antimalware Platform | < 4.18.26040.7 | 4.18.26040.7+ |
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β SOLARFLARE EXPLOIT CHAIN β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β 1. Create Working Directory β
β ββ> %TEMP%\SF-XXXX\ β
β β
β 2. Trigger Defender with EICAR β
β ββ> Write reversed EICAR to bait file β
β β
β 3. Wait for VSS Snapshot β
β ββ> Detect Volume Shadow Copy creation β
β β
β 4. Create First Batch Oplock β
β ββ> FSCTL_REQUEST_BATCH_OPLOCK on bait file β
β β
β 5. Wait for Oplock Break β
β ββ> Acquire exclusive access β
β β
β 6. Rename Directory β
β ββ> Move original directory to .tmp β
β β
β 7. Register Cloud Sync Root β
β ββ> CfRegisterSyncRoot with Cloud Files API β
β β
β 8. Create Cloud Placeholder β
β ββ> CfCreatePlaceholders for bait file β
β β
β 9. Create Second Batch Oplock β
β ββ> FSCTL_REQUEST_BATCH_OPLOCK on cloud placeholder β
β β
β 10. Wait for Second Oplock Break β
β ββ> Acquire exclusive access β
β β
β 11. Rename Cloud Directory β
β ββ> Move cloud directory to .cloud.tmp β
β β
β 12. Create NTFS Junction to System32 β
β ββ> Redirect to C:\Windows\System32 β
β β
β 13. Copy Payload to System32 β
β ββ> Copy bait file to System32 as TieringEngineService.exe β
β β
β 14. Activate Service as SYSTEM β
β ββ> CoCreateInstance(StorageTiersManagement) β
β β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
# Clone the repository
git clone https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit
cd CVE-2026-41091-PoC-Exploit
# Build using Visual Studio Developer Command Prompt
cl.exe /EHsc /std:c++17 full_poc.cpp /link cfapi.lib ntdll.lib
# Or build basic version
cl.exe /EHsc /std:c++17 basic_poc.cpp /link ntdll.lib
full_poc.exe
basic_poc.exe
CVE-2026-41091 SolarFlare PoC
===============================
by @tc4dy | CVSS 7.8
===============================