{"id":167926,"date":"2026-04-08T11:12:52","date_gmt":"2026-04-08T09:12:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft"},"modified":"2026-04-10T10:23:05","modified_gmt":"2026-04-10T08:23:05","slug":"issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft","title":{"rendered":"A researcher has leaked exploit code for Windows in response to Microsoft's inaction.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A security researcher has released a zero-day exploit code for Windows, dubbed BlueHammer. The reason for this radical step stemmed from a conflict the specialist had with Microsoft's Security Response Center (MSRC) regarding the handling of the information he provided.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2026\/04\/2826548d95da54dac5df557db876e290.jpg\" alt=\"A researcher has leaked exploit code for Windows in response to Microsoft&#039;s inaction.\" \/><\/p>\n<p>The researcher, known by the pseudonym Chaotic Eclipse, posted the exploit code on GitHub on April 3rd. The author expressed frustration at MSRC's management regarding his previous information about the incident and fundamentally refused to explain the technical details of his vulnerability disclosure method. The exploit allows a local attacker to escalate their privileges in the system to SYSTEM level or gain elevated administrator rights. Currently, Microsoft has not released a security update, only providing a standard comment on the importance of coordinated vulnerability disclosure.<\/p>\n<p>Will Dormann, the leading security analyst at Tharros, confirmed the exploit's functionality. He explained that the attack constitutes local privilege escalation, which combines a time-of-check to time-of-use (TOCTOU) vulnerability and path confusion. This complex method gives a hacker access to the Security Account Manager (SAM) database, where the hashes of local account passwords are stored. As a result, it is possible to launch a command shell with maximum privileges and fully compromise the computer.<\/p>\n<p>At the same time, both the author of the code, Chaotic Eclipse, and independent testers note the presence of bugs in the exploit, which may cause it to operate inconsistently. In particular, on the Windows Server platform, the code does not grant full system rights but only elevates them to administrator level with a confirmation prompt. Dormann suggested that Microsoft's requirement for mandatory video attachment demonstrating the hack may have irritated the author.<\/p>\n<p>Despite the fact that the vulnerability requires initial local access, hackers can easily obtain it in advance through social engineering or other software breaches.<\/p>\n<p><strong>Source:<\/strong><\/p>\n<ul class=\"related\">\n<li><a title=\"BleepingComputer\" href=\"https:\/\/www.bleepingcomputer.com\/\" target=\"_blank\" rel=\"nofollow noopener\">BleepingComputer<\/a><\/li>\n<\/ul>\n<p><center><center><\/center><center><\/center><\/center><center><\/center><br \/>\nSource: <a rel=\"nofollow\" href=\"https:\/\/3dnews.ru\/1139601\">3dnews.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0434\u043b\u044f Windows, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 BlueHammer. \u041f\u0440\u0438\u0447\u0438\u043d\u043e\u0439 \u0442\u0430\u043a\u043e\u0433\u043e \u0440\u0430\u0434\u0438\u043a\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0448\u0430\u0433\u0430 \u0441\u0442\u0430\u043b \u043a\u043e\u043d\u0444\u043b\u0438\u043a\u0442 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u0430 \u0441 \u0426\u0435\u043d\u0442\u0440\u043e\u043c \u0440\u0435\u0430\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f Microsoft (MSRC) \u0438\u0437-\u0437\u0430 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0438\u043c \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438. \u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c, \u0432\u044b\u0441\u0442\u0443\u043f\u0430\u044e\u0449\u0438\u0439 \u043f\u043e\u0434 \u043f\u0441\u0435\u0432\u0434\u043e\u043d\u0438\u043c\u043e\u043c Chaotic Eclipse, 3 \u0430\u043f\u0440\u0435\u043b\u044f \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0430 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0435 GitHub. \u0410\u0432\u0442\u043e\u0440 \u0432\u044b\u0440\u0430\u0437\u0438\u043b \u0440\u0430\u0437\u043e\u0447\u0430\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u043e\u0442\u043d\u043e\u0448\u0435\u043d\u0438\u0435\u043c \u0440\u0443\u043a\u043e\u0432\u043e\u0434\u0441\u0442\u0432\u0430 MSRC \u043a \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0438\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":167927,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-167926","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0434\u043b\u044f Windows, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 BlueHammer.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0441\u043b\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u0434\u043b\u044f Windows \u0432 \u043e\u0442\u0432\u0435\u0442 \u043d\u0430 \u0431\u0435\u0437\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 Microsoft | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0434\u043b\u044f Windows, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 BlueHammer.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-04-08T09:12:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-04-10T08:23:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Researcher leaked exploit code for Windows in response to Microsoft\u2019s inaction | ProHoster","description":"A security researcher has released a zero-day exploit code for Windows, dubbed BlueHammer.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0441\u043b\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u0434\u043b\u044f Windows \u0432 \u043e\u0442\u0432\u0435\u0442 \u043d\u0430 \u0431\u0435\u0437\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 Microsoft | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0434\u043b\u044f Windows, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 BlueHammer.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-04-08T09:12:55+00:00","article:modified_time":"2026-04-10T08:23:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/167926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=167926"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/167926\/revisions"}],"predecessor-version":[{"id":168278,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/167926\/revisions\/168278"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/167927"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=167926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=167926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=167926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}