[HN Gopher] RedSun: System user access on Win 11/10 and Server w...
       ___________________________________________________________________
        
       RedSun: System user access on Win 11/10 and Server with the April
       2026 Update
        
       Author : airhangerf15
       Score  : 170 points
       Date   : 2026-04-16 03:54 UTC (19 hours ago)
        
 (HTM) web link (github.com)
 (TXT) w3m dump (github.com)
        
       | ranger_danger wrote:
       | > normally I would just drop the PoC code and let people figure
       | it out
       | 
       | Looks like that's exactly what they did though?
       | 
       | Or maybe they just meant that they don't usually explain how it
       | works?
        
         | kijin wrote:
         | Tney gave it a sexy name and set up a website about it (a
         | github repo, at any rate), instead of just talking about it in
         | a mailing list and getting a CVE like a proper bearded security
         | researcher.
        
           | tclancy wrote:
           | It's getting warm above the equator, they may have shaved for
           | the season.
        
       | egeozcan wrote:
       | I wonder why Windows Defender has the privilege to alter the
       | system files. Read them for analysis? Sure! Reset (as in, call
       | some windows API to have it replaced with the original), why not?
       | But being able to write sounds like a bad idea.
       | 
       | However, I don't know what I'm talking about so take it with a
       | grain of salt!
        
         | EvanAnderson wrote:
         | AV had traditionally run as SYSTEM on Windows (and, in the
         | past, often had kernel mode drivers too). I've always thought
         | it was a terrible idea. It opens up exciting new attack
         | surfaces. Kaspersky and McAfee both had privilege escalation
         | vulnerabilities that I can recall. There have been a ton in
         | multiple products over the years.
        
           | labelbabyjunior wrote:
           | They kind of have to, though.
           | 
           | If malware exploits a privilege escalation vuln, what's the
           | AV going to do about it when it's reduced to the software
           | equivalent of a UK police officer? Observe and report? Stop
           | or I'll say "stop" again?
           | 
           | AV requires great power, which requires great responsibility.
           | The second part is what often eludes AV developers.
        
             | EvanAnderson wrote:
             | The OS should do the SYSTEM-level lifting and scanning
             | processes and behavior analysis should run sandboxed as low
             | priv processes. It would require a clearly defined API and
             | I feel like MSFT was always reticent to commit, leaving AV
             | manufacturers to create hacky nightmares.
        
               | labelbabyjunior wrote:
               | Well the OS should do nothing--remember MS was taken to
               | court over that--but better privsep on the part of the
               | AV, sure.
               | 
               | Technically, Defender can be replaced with 3rd party AV.
        
             | bux93 wrote:
             | Windows has separate SeBackupPrivilege for backup software,
             | so why not for AV?
        
               | arcfour wrote:
               | What would this privilege look like that is meaningfully
               | different from SYSTEM while being properly protected
               | from/able to deal with malware that has an LPE?
        
             | formerly_proven wrote:
             | "Because the remediation component requires SYSTEM, the
             | entire AV needs to run as SYSTEM and we have to unpack
             | malware in the kernel"
        
           | Fokamul wrote:
           | Because to get Ring0, you just need signed vulnerable driver.
           | 
           | There are tons of signed drivers to explore ;-)
        
         | labelbabyjunior wrote:
         | Some files under Windows are protected as the TrustedInstaller
         | user, which is a more restrictive level of permissions than
         | SYSTEM.
        
       | labelbabyjunior wrote:
       | A local privilege escalation to root via an exploitable service?
       | 
       | Doesn't Linux have one of these CVEs...each week?
        
         | hsbauauvhabzb wrote:
         | Probably, but is that service deployed as part of the base
         | operating system or a third party package? Can you remove the
         | service if you deem the crazy service behaviour is unnecessary
         | or too risky for your usecase?
        
         | hnlmorg wrote:
         | Only if you're running daemons as root. Which would be an
         | idiotic move to begin with because that's not how distros
         | package their services. So you'd have to intentionally make
         | this mistake.
        
           | GuestFAUniverse wrote:
           | Intentionally?
           | 
           | Ignorance is bliss! Simply use docker in its (old) default
           | setup, instead of podman, apptainer, docker-rootless ... and
           | that world is yours.
           | 
           | Added bonuses are the incredible stupid integration with ufw
           | on Ubuntu, images with laughable uid mapping, ...
           | 
           | How that shit got traction baffles me.
        
             | hnlmorg wrote:
             | That's just the docker daemon. The actual docker services
             | would (or at least _should_ ) still be running as its own
             | user/group just like they would if you were running them on
             | the host.
             | 
             | And that's exactly how any reputable image would be built.
        
         | BodyCulture wrote:
         | No.
        
         | IshKebab wrote:
         | Not quite every week, but yeah it has a lot. And if the target
         | uses sudo at all you don't even need an exploit!
         | 
         | But nobody mentioned Linux. There's no need for whataboutism.
         | They both shouldn't have these vulnerabilities.
        
           | hnlmorg wrote:
           | > And if the target uses sudo at all you don't even need an
           | exploit!
           | 
           | Why would a target executable use sudo? There are proper
           | mechanisms for automated elevation of permissions and sudo
           | isn't it.
           | 
           | sudo is designed for user interactivity. And by default
           | prompts for a password. However some people get lazy and
           | disable the password entry requirement.
        
             | IshKebab wrote:
             | A target _user_. If you get local code execution on the
             | account of a user that uses sudo you can trivially got
             | root. Doesn 't matter if they disabled the password
             | authentication or not.
        
               | hnlmorg wrote:
               | Of course it matters if they disabled password
               | authentication. If you require password authentication
               | when running sudo then an attacker has to find a RCE
               | exploit _and then_ crack a password. Which is waaay
               | beyond any effort the average attacker is willing to
               | invest. Because At that point, root access isn't really
               | worth the effort.
               | 
               | An attacker will probably just use the host for sending
               | spam emails, bot / DDoS traffic or look for other daemons
               | they can jump to which weren't web accessible (eg a
               | database).
               | 
               | And furthermore, if you've got a RCE in a daemon then
               | that code is the running as the daemons' user. Which
               | shouldn't be in the sudoers file (eg wheel group) to
               | begin with.
        
       | hathym wrote:
       | cl /std:c++17 /EHsc /W4 /O2 /DUNICODE /D_UNICODE /wd4005
       | /Fe:RedSun.exe RedSun.cpp advapi32.lib ole32.lib user32.lib
        
         | technion wrote:
         | Seriously this is my bugbear with code for windows: how did you
         | figure that invocation out?
         | 
         | Anything for Linux you just type "make". If the author skipped
         | a makefile, theres rarely much to it.
         | 
         | But when someone has a cpp file for Windows it looks like this.
        
       | IFC_LLC wrote:
       | I remember the times when Microsoft had a lot of problems 20
       | years ago because of Sasser and other viruses that were taking
       | over Windows. They did not have any contenders. Yet they have
       | stopped any software development for 9 months just to re-work
       | their entire codebase to prevent things like direct memory
       | execution and stuff like that. The result of that was Windows XP
       | Service Pack 2. After that thing windows XP became a legend.
       | 
       | Now, when Linux is slowly creeping on one side, and Mac NEO on
       | another they keep releasing this AI-slop.
       | 
       | By the looks of it they make most of their money from the cloud
       | and other software things nowadays. And Windows has become a
       | sidekick in their processes.
        
         | nailer wrote:
         | > Windows XP Service Pack 2. After that thing windows XP became
         | a legend.
         | 
         | God that was an era. XP SP2 was a great OS, IE was the best
         | browser, MSN was the most popular messenger, Skype was
         | acquired, HTC's Windows CE devices were shipping real web
         | browsers that worked over 3G.
         | 
         | By the end of the Ballmer era, Microsoft has lost the OS, the
         | browser, the messenger, the meeting service and mobile.
        
           | uep wrote:
           | I agree with you on everything except the browser. I'm pretty
           | sure I was using Firefox (or maybe Opera?) on Windows before
           | the release of Vista. I know I was still using IE for some
           | ActiveX web apps for a while. This was the era that I
           | switched over to Linux full-time, but both Windows 2000 and
           | XP were great OSes at this time. Linux was painful to adopt,
           | but I really loved the promise of "full-control" over my
           | computer.
           | 
           | My peeve today is how bad modern chat programs feel compared
           | to the old instant messengers. The modern programs all feel
           | slow and clunky in comparison. I felt that all of the
           | messengers I used (MSN, AIM, ICQ) were more responsive than
           | their modern day equivalents.
        
             | IFC_LLC wrote:
             | Boy oh boy, have we forgotten the Maxthon?
             | https://en.wikipedia.org/wiki/Maxthon
             | 
             | I remember the times when IE passed ACID test? Do we
             | remember the ACID? http://acid2.acidtests.org/#top
             | 
             | Ah, what the times were those. Firefox was just gaining
             | traction.
             | 
             | And I agree. Slack is sitting there, consuming over gig of
             | memory on my computer, and Miranda NG was able to do the
             | same functionality with cool skins and just 30 megs of ram.
             | 
             | Skins... Skins... We've lost even those...
        
               | hulitu wrote:
               | > Boy oh boy, have we forgotten the Maxthon?
               | 
               | Never heard about it (Europe).
        
             | IFC_LLC wrote:
             | https://gs.statcounter.com/browser-market-
             | share#monthly-2009...
             | 
             | Yes, I've just checked, even in 2009 you still have IE over
             | 64% of browser usage.
        
               | uep wrote:
               | They said IE was the best browser, not the most popular.
               | I wouldn't dispute that IE was more commonly used at the
               | time.
               | 
               | Just checked your link and this fits with what I thought
               | in terms of marketshare. You can see that Firefox was
               | ~25% of marketshare in 2009. Which is an enormous share
               | of the pie when you consider that they couldn't stick a
               | download link on the front page of the most dominant
               | search engine, and it didn't come preinstalled.
               | 
               | Never used Maxthon.
               | 
               | Damn, this also reminded me that RSS feeds were
               | everywhere back then, and the browser supported it
               | directly.
        
               | IFC_LLC wrote:
               | Oh don't tell me about Nero, Winamp, eMule, Download
               | managers, auto-dialers, free internet on Saturdays after
               | 2am till 9am, miranda NG, PHPBB, etc.
               | 
               | The internet was awesome.
        
               | nailer wrote:
               | > They said IE was the best browser, not the most
               | popular.
               | 
               | TBF I should have said 'most popular' for all those
               | categories.
        
         | toyg wrote:
         | I don't think SP2 made much of a difference in the popularity
         | of XP. It was already dominant, and it's mostly remembered as
         | "legendary" because it had become the target platform for every
         | hardware and software vendor on the planet. Windows 98 was too
         | flaky to engender any serious friction to upgrades, and Windows
         | 2000 was not consumer-friendly enough; XP effectively unified
         | the consumer and professional desktop markets, and became the
         | gold standard.
         | 
         | SP2, if anything, _slowed down_ adoption, since it threw a
         | bunch of spanners in the way of third-party code. It was
         | probably necessary, just to stem the flow of bad press, but no
         | mean a key in XP 's overall success.
        
           | IFC_LLC wrote:
           | It was not that bad. I remember when SP fixed a bunch of
           | issues with bluetooth, and windows CD burning program was
           | better than any of the Nero Burning ROMs, cause those became
           | unusable overbloated.
        
           | steve1977 wrote:
           | Also, technically XP was Windows NT 5.1, so it was built on a
           | solid basis.
           | 
           | Whereas 98 was still in the kinda DOS-based 9x line.
           | 
           | And I fully agree with you to not mention Windows Me.
        
           | hulitu wrote:
           | > I don't think SP2 made much of a difference in the
           | popularity of XP
           | 
           | The general knowledge was to wait until the SP were stable.
           | This was hard. 4.0 had SP6, 2k had SP4.
        
         | orbital-decay wrote:
         | There were several points in time (after the SP2 too) when
         | installing WinXP with an active internet connection was nearly
         | impossible, because it would get infected during the
         | installation and shut itself down halfway through it.
        
       | luma wrote:
       | Tried to download and Defender blocks it.
        
         | trollbridge wrote:
         | That's how the exploit works.
        
           | luma wrote:
           | I can't seem to find any system files replaced, and the .exe
           | was never executed. I'm running this in a test VM, but from
           | what I can see, Defender signatures have been updated to
           | block this prior to execution.
           | 
           | The exploit, from my reading, needs to be executed in order
           | to do it's thing, but Defender isn't allowing it to be
           | written to the filesystem on download.
        
             | molticrystal wrote:
             | What is Defender marking it as? I also wonder if they are
             | just special casing this program and it would work again if
             | the code was shuffled a bit or if it used the AMSI sig [0]
             | instead of EICAR or if they actually fixed the problem.
             | 
             | [0] https://github.com/Roadmvn/C-Full-Offensive-
             | Course/blob/main...
        
               | luma wrote:
               | Detected: Program:Win32/Wacapew.C!ml
               | 
               | With a link to: https://www.microsoft.com/en-
               | us/wdsi/threats/malware-encyclo...
        
       | lexicality wrote:
       | helpfully the user provides a second tool which automatically
       | turns off Windows Defender so you can't be affected by this:
       | https://github.com/Nightmare-Eclipse/UnDefend
        
         | layer8 wrote:
         | > It runs in two modes, passive and aggressive
         | 
         | Lol
        
           | hulitu wrote:
           | Unlike Windows Defender which is passive aggressive.
        
       | Implement7347 wrote:
       | I'd love to think that this person is a rogue AI, (better than
       | Claude mythos?) Dropping two zero days in one month is pretty
       | interesting. Nice work.
        
       | Dwedit wrote:
       | Any way to disable the entire cloud tag system?
        
       ___________________________________________________________________
       (page generated 2026-04-16 23:01 UTC)