news.mlab.sh
Back to the feed
vulnerability

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

High
Summary

A security researcher, Chaotic Eclipse (MSNightmare), has released a proof-of-concept exploit, RoguePlanet, targeting a zero-day vulnerability in Microsoft Defender, granting SYSTEM-level access on updated Windows 11 and 10 systems. This follows a public dispute with Microsoft over the handling of the vulnerability disclosure and subsequent takedown of the researcher’s online accounts. The vulnerability has been exploited in the wild.

The exploit, a race condition, allows an attacker to gain SYSTEM-level privileges on Windows 11 and 10 machines running the June 2026 Patch Tuesday updates. While the researcher claims a 100% success rate on some machines, it’s not consistently reliable. The vulnerability primarily affects standard user installations, but does not function on Windows Server instances due to the inability to mount ISO images. The researcher has identified additional memory corruption vulnerabilities within Defender and other components. This disclosure follows a contentious period where the researcher publicly criticized Microsoft's handling of the vulnerability, alleging a retaliatory effort and accusing the company of revoking access to the Microsoft Security Response Center (MSRC) and defaming the researcher. Microsoft has responded by condemning the public disclosures and stating they are ‘never justifiable’ and put customers at ‘unnecessary risk’.

Read the full article at The Hacker News