New RoguePlanet zero-day grants SYSTEM access via Windows Defender exploit, raising security concerns.

The researcher published RoguePlanet after Microsoft removed earlier exploits from major code-hosting sites: the PoC appeared on a self-hosted Git repository “after Microsoft had previous exploits removed from GitHub and GitLab,” framing the release as part of a wider dispute over disclosure and access to code.
Microsoft’s mid-May hardening was specifically described as a fix to Defender’s “mpengine,” which forced Chaotic Eclipse/Nightmare-Eclipse to rewrite the exploit from earlier approaches into a local privilege-escalation path.
The researcher said the RoguePlanet work initially began as a remote-code-execution technique involving Defender’s handling of files on remote SMB shares—requiring coercing a victim to open a “.vhd(x) file on a remote SMB server,” which (the researcher claimed) would cause Defender to overwrite its own files.
Chaotic Eclipse/Nightmare-Eclipse published RoguePlanet using a new GitHub identity, “MSNightmare,” and claimed extreme variance in reliability—stating they achieved a “100% success rate on some systems” while other machines were inconsistent due to the race-condition timing.
Independent security researcher Will Dormann confirmed the PoC’s behavior with a direct comment on Mastodon: “it’s reportedly not 100% reliable, but it worked on the first attempt for me.”
A security researcher known as Chaotic Eclipse dropped a new Windows Defender zero-day called RoguePlanet on June 10, 2026 — the same day Microsoft issued its monthly Patch Tuesday updates. The exploit abuses a race condition in Defender to hand an attacker a full SYSTEM-level command shell on fully patched Windows 10 and 11 machines, according to Cyber Kendra and Crypto Briefing.
Independent researcher Will Dormann verified it quickly. He wrote on Mastodon: "It's reportedly not 100% reliable, but it worked on the first attempt for me." The release marks the seventh zero-day from this researcher since April 2026 — roughly one every ten days.
RoguePlanet exploits a race condition — a flaw where two processes compete over a shared resource at the wrong moment. By winning that race inside Windows Defender, the exploit lets an attacker replace a normal user session with a SYSTEM shell. SYSTEM is the highest privilege level on a Windows machine. It sits above even an administrator account.
The researcher said success rates varied wildly. On some test machines, they claimed a "100% success rate." On others, timing issues caused failures. That inconsistency comes from the nature of race conditions — they depend on split-second timing that differs across hardware and system load, according to Cyber Kendra.
Chaotic Eclipse published RoguePlanet on a self-hosted Git server and under a new GitHub identity called "MSNightmare." The move came after Microsoft had previous exploits pulled from GitHub and GitLab, according to Real Hacker News. The researcher framed this as an escalating fight over who controls access to vulnerability research.
This is the sixth or seventh public zero-day from the same researcher since early April. Chaotic Eclipse has averaged one release every ten days. Some security blogs now treat the researcher as a threat actor rather than a reporter of bugs, citing rapid pickup of their code by ransomware groups and infrastructure traced to Russian geolocations, according to Crypto Briefing.
RoguePlanet started as a remote-code-execution attack, not a local one. The researcher originally targeted Defender's handling of .vhd and .vhdx files — virtual hard disk formats — on remote SMB file shares. The idea was that Defender would overwrite its own files while scanning such a file, triggering code execution without any local access needed.
Microsoft quietly hardened Defender's core engine, called mpengine, in mid-May. That update broke the remote attack path entirely. The researcher was forced to rewrite the exploit as a local privilege escalation instead. Chaotic Eclipse called the rewrite "soul-draining," adding: "Microsoft's efforts to protect Defender from path redirection attacks are useless."
Microsoft released Defender definition update 1.453.20.0 on June 10 after RoguePlanet went public. The update is designed to detect and quarantine the specific proof-of-concept code. But security experts cautioned that the protection could be bypassed with minor changes to the exploit, according to Crypto Briefing and Techno Bezz.
The current exploit does not affect Windows Server in the same way, due to default restrictions on mounting VHD images. Enterprises are being urged to enable application allowlisting tools like AppLocker as a stronger mitigation. The risk is especially high for anyone storing cryptocurrency wallet files or private keys on an affected machine. SYSTEM access lets an attacker dump memory and extract credentials that a standard user account could never reach.
Publishers
18
Articles
1
Reach
19