Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
A disgruntled researcher known as Nightmare-Eclipse has released another proof-of-concept (PoC) exploit, dubbed RoguePlanet, targeting a Windows Defender vulnerability. This follows a series of similar disclosures aimed at Microsoft, highlighting a protracted feud and raising concerns about unpatched vulnerabilities falling into the hands of malicious actors. The researcher’s actions, coupled with Microsoft’s initial silence and subsequent condemnation, underscore the complexities of vulnerability disclosure and the potential risks associated with irresponsible disclosures.
The ongoing conflict between a researcher, operating under the pseudonym Nightmare-Eclipse, and Microsoft has escalated with the release of the RoguePlanet PoC exploit. This exploit targets a race condition within Windows Defender, allowing for SYSTEM-level access to compromised Windows machines. The researcher, who spent most of May developing the PoC, released it shortly after Microsoft’s Patch Tuesday updates, mirroring their previous actions with other zero-day vulnerabilities. Notably, the PoC currently doesn't function on Windows Server due to limitations with mounting ISO images, though the researcher acknowledged this could be bypassed.
This situation is fueled by a history of disputes, beginning with the release of the BlueHammer exploit in April, tracked as CVE-2026-33825. Nightmare-Eclipse initially went by the name Chaotic Eclipse and threatened further disclosures in retaliation for Microsoft’s handling of reported vulnerabilities. Following the disclosure of BlueHammer, the researcher released five additional PoCs – RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma – prompting Microsoft to release patches. However, the continued release of PoCs poses a significant risk to Microsoft customers, even with the availability of fixes.
Microsoft’s response to the initial disclosures, characterized by silence and a threat of criminal charges, drew criticism from the security community. Trend Micro’s Dustin Childs highlighted the potential impact on customers, emphasizing the need for proactive patching. The situation underscores the challenges of responsible vulnerability disclosure and the potential consequences of uncoordinated disclosures falling into the wrong hands.
