{"id":48815,"date":"2026-04-22T13:38:30","date_gmt":"2026-04-22T13:38:30","guid":{"rendered":"http:\/\/localhost\/?p=48815"},"modified":"2026-04-22T13:38:30","modified_gmt":"2026-04-22T13:38:30","slug":"dontwait-for-a-patch-mitigate-redsunzero-day-risk-in-microsoft-defender-today","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=48815","title":{"rendered":"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-22T18:29:09&#8243;,&#8221;description&#8221;:&#8221;### Key Takeaways\\n\\n  * RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM access\\n  * No patch is currently available, leaving all Defender-enabled Windows systems potentially exposed\\n  * Qualys VMDR detects affected assets instantly (QID 92382)\\n  * TruRisk![\u2122](https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72&#215;72\/2122.png) Eliminate enables immediate mitigation, removing exploitability without waiting for a fix\\n  * Organizations can reduce or eliminate risk in real time, with validated mitigation and TruRisk score updates\\n\\n\\n\\n* * *\\n\\nRedSun is a zero-day local privilege escalation (LPE) vulnerability in Microsoft Defender. It allows a low-privileged user to gain full SYSTEM-level access on Windows without any kernel exploit or administrator interaction.   \\n   \\nWhat makes RedSun especially dangerous is that it weaponizes a trusted, always-on security component. Most enterprise environments have Defender running continuously, making the attack surface universal across unpatched Windows fleets. \\n\\n## **Key characteristics**\\n\\nVulnerability type | Local Privilege Escalation (LPE)   \\n&#8212;|&#8212;  \\nAffected component | Microsoft Defender (cloud file restoration logic)   \\nRequired privileges | Low (standard user)   \\nAffected OS | Windows 10, Windows 11, and Windows Server 2019 and later systems   \\nPatch status | No vendor patch currently available   \\nAttack complexity | Low \u2014 minimal prerequisites required   \\n  \\nBecause no official patch exists, traditional remediation workflows fall short. This blog walks through how Qualys VMDR detects RedSun across your environment and how TruRisk![\u2122](https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72&#215;72\/2122.png) Eliminate enables teams to deploy targeted mitigations for measurable risk reduction, even without a vendor fix. \\n\\n* * *\\n\\n**Try TruRisk Eliminate today to see how you can mitigate the RedSun** **vulnerability**.\\n\\nTry TruRisk Eliminate today\\n\\n* * *\\n\\n## **How Does the  RedSun Vulnerability Exploit Chain Work? **\\n\\nAt its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation. When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it. This restore operation runs with full NT AUTHORITY\\\\SYSTEM privileges and critically does not validate whether the target path has been tampered with.   \\n   \\nWhen Defender remediates a threat, it performs privileged file operations (move, delete, or restore) running as NT AUTHORITY\\\\SYSTEM. RedSun exploits improper handling of these operations: a low-privileged user can influence the target path involved in the remediation action, redirecting SYSTEM-level file writes to attacker-controlled locations.\\n\\n## **How to  Detect RedSun Exposure with Qualys VMDR**\\n\\nQualys VMDR provides comprehensive detection and visibility for RedSun across your entire Windows endpoint estate.   \\n\\n\\nUse the following QQL query to instantly surface all assets with the RedSun detection (QID 92382) in your VMDR: \\n    \\n    \\n    vulnerabilities.vulnerability.qid:92382\\n\\n![How to\u00a0Detect\u00a0RedSun\u00a0Exposure with Qualys VMDR](https:\/\/blog.qualys.com\/wp-content\/uploads\/2026\/04\/Detect-RedSun-Exposure-with-Qualys-VMDR-scaled.png)\\n\\n## **How to  Mitigate RedSun With No Patch Using TruRisk![\u2122](https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72&#215;72\/2122.png) Eliminate**\\n\\nSince no patch is currently available for RedSun, mitigation becomes the primary line of defense. Waiting for a vendor fix is not an option when exploitability is low-complexity, and the attack surface spans every Windows endpoint with Defender enabled.   \\n  \\nQualys TruRisk![\u2122](https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72&#215;72\/2122.png) Eliminate bridges this gap by enabling security teams to deploy targeted, script-based mitigation actions directly from the VMDR platform, with no separate tooling or manual endpoint access required. Each action is designed to reduce or fully eliminate the exploitability of a specific vulnerability, and the resulting risk reduction. \\n\\n### Mitigation for RedSun Vulnerability can include: \\n\\nThe mitigation involves the disabling of the Cloud Files Mini Filter service, which prevents the Windows Cloud Files platform from loading and blocks cloud file placeholder and on\u2011demand file hydration functionality. This helps restrict OS\u2011level cloud file system integrations such as OneDrive Files On\u2011Demand.\\n\\n![Mitigation for\u00a0RedSun\u00a0Vulnerability](https:\/\/blog.qualys.com\/wp-content\/uploads\/2026\/04\/Mitigation-for-RedSun-Vulnerability-scaled.png)\\n\\nOnce applied, the mitigation status for each host is immediately updated and clearly reflected in VMDR, giving security teams audit-ready proof of compensating controls. These statuses are clearly reflected in VMDR, giving teams assurance and audit-ready visibility while they prepare permanent remediation.\\n\\n![Mitigation for RedSun](https:\/\/blog.qualys.com\/wp-content\/uploads\/2026\/04\/Mitigation-for-RedSun-Vulnerability-2-1.png)\\n\\n## 3 Key Outcomes\\n\\nRedSun is a stark reminder that modern attackers no longer need to find exotic zero-days or bypass kernel protections. They can weaponize the very security tools designed to protect your endpoints. A low-privileged user with access to a Windows machine can escalate to SYSTEM simply by abusing Defender\u2019s own remediation behavior.\\n\\nThis vulnerability underscores three key takeaways for security teams:\\n\\n  1. **Patch cycles alone are no longer sufficient.** Zero-days demand a risk-based mitigation strategy that operates independently of vendor timelines.\\n  2. **Trusted components are high-value targets.** Security software running at elevated privilege is an attractive attack surface and should be treated accordingly.\\n  3. **Visibility and mitigation must be unified.** Knowing you\u2019re vulnerable is only half the battle. The ability to act immediately at scale is what separates managed risk from unmanaged exposure.\\n\\n\\n\\nQualys VMDR and TruRisk![\u2122](https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72&#215;72\/2122.png) Eliminate together provide exactly that: continuous detection, quantified risk, and actionable mitigation, keeping organizations resilient even when the vendor hasn\u2019t shipped a patch.\\n\\n* * *\\n\\nIf you already are a Qualys customer:   \\nContact your TAM to find out how to mitigate the risk of RedSun now.  \\n\\nNew to Qualys?  \\nSign up for a complimentary trial of TruRisk Eliminate today\\n\\nStart Your TruRisk Eliminate Trial\\n\\n* * *\\n\\n## Frequently Asked Questions (FAQs)\\n\\n**What is the  RedSun vulnerability?** \\n\\nRedSun is a zero-day local privilege escalation (LPE) vulnerability in Microsoft Defender that allows a low-privileged user to gain NT AUTHORITY\\\\SYSTEM access by exploiting flaws in the remediation workflow. \\n\\n**Why is  RedSun considered critical?** \\n\\nIt combines low attack complexity, no required privileges, and broad exposure across Windows systems running Defender\u2014making it highly exploitable in real-world environments. \\n\\n**Is there a patch available for  RedSun?** \\n\\nNo. At the time of writing, no vendor patch is available, which makes traditional patch-based remediation ineffective. \\n\\n**How can organizations detect  RedSun exposure?** \\n\\nUsing Qualys VMDR, teams can identify affected assets with the QQL query: \\n    \\n    \\n    vulnerabilities.vulnerability.qid:92382\\n\\n**How can you mitigate  RedSun without a patch?** \\n\\nUsing Qualys TruRisk Eliminate, teams can mitigate this vulnerability. \\n\\n**What is  TruRisk![\u2122](https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72&#215;72\/2122.png) Eliminate and how does it help?** \\n\\nTruRisk![\u2122](https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72&#215;72\/2122.png) Eliminate enables teams to deploy targeted mitigation and remediation actions directly from the Qualys platform, eliminating vulnerability exploitability\u2014even when no patch exists. \\n\\n**Does mitigation actually reduce risk if the vulnerability still exists?**  \\n\\nYes. While the vulnerability may still be present, effective mitigation removes its exploitability, which reduces or eliminates real-world risk. \\n\\n**How is risk reduction  validated?** \\n\\nEach mitigation action is: \\n\\n  * Executed at scale\\n  * Continuously validated  \\n  * Reflected in the QDS score, providing measurable and auditable proof of risk reduction  \\n\\n\\n\\n**Why is this important for security teams?**  \\n\\nBecause threats move faster than patch cycles, teams need the ability to: \\n\\n  * Act immediately  \\n  * Reduce risk proactively  \\n  * Maintain visibility and control across all endpoints&#8221;,&#8221;published&#8221;:&#8221;2026-04-22T17:12:34&#8243;,&#8221;modified&#8221;:&#8221;2026-04-22T17:12:34&#8243;,&#8221;type&#8221;:&#8221;qualysblog&#8221;,&#8221;title&#8221;:&#8221;Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;QUALYSBLOG:D571338800CB27456FC1CDF88B86897D&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/blog.qualys.com\/category\/product-tech\/vulnmgmt-detection-response&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-22T18:29:09&#8243;,&#8221;description&#8221;:&#8221;### Key Takeaways\\n\\n * RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM access\\n * No patch is&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,13,33,120,7,11,5],"class_list":["post-48815","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-news","tag-none","tag-qualysblog","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=48815\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-04-22T18:29:09&#8243;,&#8221;description&#8221;:&#8221;### Key Takeawaysnn * RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM accessn * No patch is...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=48815\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-22T13:38:30+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48815#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48815\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D\",\"datePublished\":\"2026-04-22T13:38:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48815\"},\"wordCount\":1382,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"news\",\"NONE\",\"qualysblog\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=48815#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48815\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48815\",\"name\":\"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-04-22T13:38:30+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48815#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=48815\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=48815#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=48815","og_locale":"en_US","og_type":"article","og_title":"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-04-22T18:29:09&#8243;,&#8221;description&#8221;:&#8221;### Key Takeawaysnn * RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM accessn * No patch is...","og_url":"https:\/\/zero.redgem.net\/?p=48815","og_site_name":"zero redgem","article_published_time":"2026-04-22T13:38:30+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=48815#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=48815"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D","datePublished":"2026-04-22T13:38:30+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=48815"},"wordCount":1382,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","news","NONE","qualysblog","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=48815#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=48815","url":"https:\/\/zero.redgem.net\/?p=48815","name":"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-04-22T13:38:30+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=48815#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=48815"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=48815#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Don\u2019t\u00a0Wait for a Patch. Mitigate RedSun\u00a0Zero-Day Risk in Microsoft Defender Today_QUALYSBLOG:D571338800CB27456FC1CDF88B86897D"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/48815","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=48815"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/48815\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=48815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=48815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=48815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}