news.mlab.sh
Back to the feed
vulnerability

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges

High
Summary

A new Microsoft Defender zero-day vulnerability, dubbed "RoguePlanet," has emerged, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and 11 systems via a race condition. The vulnerability was discovered by Nightmare Eclipse and successfully exploited by ThreatLocker, highlighting the ongoing challenges of securing Windows systems despite patching. This incident underscores the importance of application allowlisting and continuous monitoring for emerging threats.

The vulnerability, "RoguePlanet," was initially developed as a remote code execution (RCE) flaw targeting Microsoft Defender’s handling of SMB shares. The exploit leverages a race condition, requiring a victim to open a .vhd(x) file on a remote SMB server, leading to Defender overwriting its own files and granting the attacker SYSTEM privileges. Nightmare Eclipse initially tested the exploit against Windows 11 Official and Canary builds, as well as Windows 10 systems with the June 2026 security updates. ThreatLocker successfully reproduced the flaw against Windows 11 systems with KB5094126 installed, demonstrating its viability. Furthermore, the researcher claims Microsoft hardened Defender in mid-May by patching the "mpengine!SysIO" API, blocking junction attacks, which initially impacted the functionality of RoguePlanet. This incident is part of a larger dispute between Nightmare Eclipse and Microsoft regarding vulnerability disclosure practices, with the researcher having previously released multiple Windows zero-days.

Read the full article at BleepingComputer