{"id":1246,"date":"2026-06-10T06:57:40","date_gmt":"2026-06-10T06:57:40","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1246"},"modified":"2026-06-10T06:57:40","modified_gmt":"2026-06-10T06:57:40","slug":"microsoft-defender-rogueplanet-zero-day-grants-system-access-on-updated-windows","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1246","title":{"rendered":"Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 10, 2026<\/span><\/span><span class=\"p-tags\">Zero-Day \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEibnTGKGBThpUUZgwRx8hcclb0nuPbrV9o3MSZhFoGEp_3DLGRzdJVpj8Xfrnk1cEPUu76_u8R5Lpt10tcaWPUlbHMwbY225I3jyiBx91pYb4dmdBFbDYVai8DS3UcXAk98dTqEuyW0r3D5c2OaHHaXJzRyCAwS32tpmB83cAJRwKxI4GIT2iGnrdBI_EV7\/s1700-e365\/windows-exploit.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/06\/its-patch-tuesday.html\">released<\/a> a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-day named <b>RoguePlanet<\/b>.<\/p>\n<p>\u00abThe exploit is a race condition, so it&#8217;s a hit or miss,\u00bb the researcher, who published the exploit under a new GitHub account, \u00abMSNightmare\u00bb <a href=\"https:\/\/github.com\/MSNightmare\/RoguePlanet\">said<\/a>. \u00abI have managed to get a 100% success rate on some machines while it struggled to work on others.\u00bb<\/p>\n<p>Should the exploit succeed, the result is a shell with SYSTEM-level privileges, granting the attacker the ability to run arbitrary code or perform unauthorized actions.<\/p>\n<p>The researcher said the exploit has been tested on Windows 11 and 10 machines with the June 2026 Patch Tuesday updates installed, meaning the exploit works on the up-to-date versions of the desktop operating system.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>That said, the exploit does not work on Windows Server instances in its current form since \u00abstandard users cannot mount an ISO image.\u00bb Chaotic Eclipse emphasized that Windows Server installations are also vulnerable to the flaw and that the exploit needs to be redesigned for it to work.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abGetting this PoC to work genuinely drained my soul, it severely degraded my mental and physical health but in the end of May [sic], a full PoC was developed,\u00bb the researcher said.<\/p>\n<p>\u00abMicrosoft&#8217;s efforts to protect Defender from path redirection attacks are useless, I have a batch of memory corruption vulnerabilities in defender as well and not to mention the other batch of vulnerabilities I have in several other components.\u00bb<\/p>\n<p><iframe loading=\"lazy\" title=\"RoguePlanet Privilege Escalation Demo\" width=\"500\" height=\"375\" src=\"https:\/\/www.youtube.com\/embed\/3v-4-HQMT7U?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p style=\"text-align: center;\"><i>Video Credit: <a href=\"https:\/\/x.com\/ThreatLocker\/status\/2064462208793202873\" target=\"_blank\">ThreatLocker<\/a><\/i><\/p>\n<p>Security researcher Will Dormann, in a post <a href=\"https:\/\/infosec.exchange\/@wdormann\/116722435763533255\">shared<\/a> on Mastodon, said \u00abit&#8217;s reportedly not 100% reliable, but it worked on the first attempt for me.\u00bb<\/p>\n<p>RoguePlanet is the latest in a series of flaws uncovered by Chaotic Eclipse in recent months &#8211;<\/p>\n<p>These uncoordinated disclosures are part of what&#8217;s assessed to be a retaliatory effort following an alleged breakdown in communication between the researcher, who has not publicly identified themselves, and Microsoft.<\/p>\n<p>In cryptographically signed posts on their Blogger page, Chaotic Eclipse expressed dissatisfaction with the way Microsoft handled the disclosure process and called out the company for revoking access to their Microsoft Security Response Center (MSRC) account, where researchers can report vulnerabilities. The researcher has also accused Redmond of humiliating them, dismissing their reports, failing to compensate them for the identified vulnerabilities, and defaming them.<\/p>\n<p>Late last month, Microsoft condemned the public vulnerability disclosures, stating they are \u00abnever justifiable\u00bb and put customers at \u00abunnecessary risk.\u00bb It&#8217;s worth noting that all three aforementioned Defender vulnerabilities have since been exploited in the wild.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The public feud has also resulted in the takedown of their GitHub and GitLab accounts. \u00abMicrosoft is attempting to misuse its ownership of GitHub to protect only its own products, and misuse its extensive links to law enforcement by branding publishing information about vulnerabilities in its own products as criminal behaviour,\u00bb security researcher Kevin Beaumont <a href=\"https:\/\/doublepulsar.com\/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4\">said<\/a>.<\/p>\n<p>\u00abTo be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research,\u00bb Microsoft <a href=\"https:\/\/x.com\/msftsecresponse\/status\/2061293718942908925\">said<\/a> in an X post. \u00abWhen an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate.\u00bb<\/p>\n<p>\u00abWe are committed to approaching every interaction with transparency, clear communication, and professionalism. We continue to believe strongly in Coordinated Vulnerability Disclosure as the foundation for protecting customers and improving our products.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 10, 2026Zero-Day \/ Vulnerability The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-day&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1247,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,1246,1567,147,1987,1045,1988,307,126],"class_list":["post-1246","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-defender","tag-grants","tag-microsoft","tag-rogueplanet","tag-system","tag-updated","tag-windows","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1246"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1246\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1247"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}