Critical Windows Defender Zero-Day Lets Attackers Gain SYSTEM Access
Key Takeaways A new zero-day exploit, “RoguePlanet,” targeting Microsoft Windows Defender has been publicly released by security researcher Nightmare Eclipse. The exploit leverages a race...
Key Takeaways
- A new zero-day exploit, “RoguePlanet,” targeting Microsoft Windows Defender has been publicly released by security researcher Nightmare Eclipse.
- The exploit leverages a race condition to achieve SYSTEM-level privileges on Windows 10 and 11 systems, including those fully patched as of June 2026.
- This vulnerability allows an unprivileged local user to gain the highest possible access on a compromised machine.
- Microsoft has not yet assigned a CVE or released a patch for RoguePlanet, despite the active exploitation of previous tools from the same researcher.
New Windows Defender Zero-Day “RoguePlanet” Grants SYSTEM Access
A critical zero-day vulnerability in Microsoft Windows Defender has been publicly exposed with the release of a new proof-of-concept (PoC) exploit named RoguePlanet. Developed by security researcher Nightmare Eclipse, also known as Chaotic Eclipse and Dead Eclipse, the exploit targets a previously undisclosed race condition within Microsoft’s antivirus software.
Table Of Content
Successful execution of RoguePlanet results in the spawning of a command shell operating with SYSTEM-level privileges, effectively granting an attacker complete control over a compromised Windows system. The exploit’s public release on GitHub coincides with Patch Tuesday, June 10, 2026, intensifying concerns amid a series of recent disclosures targeting Defender.
Understanding the RoguePlanet Exploit
RoguePlanet functions as a local privilege escalation (LPE) exploit, exploiting a race condition inherent in Microsoft Defender’s internal processes. An unprivileged local user can leverage this flaw to redirect a file operation performed by Defender, which typically runs with SYSTEM privileges. This redirection allows the attacker to execute their own code at the highest privilege level available on the system.
The researcher has confirmed RoguePlanet’s efficacy on fully updated Windows 10 and Windows 11 systems, encompassing both stable releases and Canary Insider Preview channels, even with the June 2026 patches applied. While Windows Server installations are also deemed vulnerable to the underlying flaw, the current PoC is not directly functional in those environments due to a prerequisite involving ISO image mounting, which standard users cannot perform on servers.
The core vulnerability is a Time-of-Check to Time-of-Use (TOCTOU) race condition. This class of vulnerability was previously exploited by Nightmare Eclipse in the BlueHammer exploit (CVE-2026-33825), which carried a CVSS score of 7.8 (High) and was addressed by Microsoft in April 2026. In that prior instance, Defender’s file remediation engine performed privileged write operations without adequate validation of file paths, allowing attackers to introduce NTFS junction points that rerouted Defender’s SYSTEM-level writes into the C:WindowsSystem32 directory.
RoguePlanet employs a similar path-redirection technique, indicating that Microsoft’s efforts to mitigate this specific class of attack within Defender may still be incomplete.
A Pattern of Disclosures and Real-World Impact
RoguePlanet is the latest in a series of zero-day disclosures by Nightmare Eclipse, who has reportedly released at least seven Defender-related exploits since early April 2026. This extensive list includes BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma.
The cybersecurity community widely perceives this ongoing campaign as a retaliatory measure following disagreements with Microsoft concerning responsible disclosure practices and account terminations. Notably, researchers at Huntress have already observed real-world intrusions leveraging earlier tools from this researcher, with BlueHammer, RedSun, and the Defender-disruption tool UnDefend documented in active attack chains.
The success rate of RoguePlanet can fluctuate across different environments. While the researcher reports a 100% success rate on some machines, the exploit’s effectiveness may vary on others, a common characteristic of race condition vulnerabilities. Although the current exploit does not function on Windows Server, all Server versions are believed to be susceptible to the underlying flaw, requiring a modified attack vector.
As of this publication, Microsoft has not yet issued a CVE identifier or a public advisory for RoguePlanet. Given the documented active exploitation of previous tools developed by Nightmare Eclipse, organizations utilizing Windows 10 or Windows 11 endpoints should prioritize this disclosure and closely monitor Microsoft’s Security Update Guide for an expedited patch.
What You Should Do
- Monitor Microsoft’s Security Update Guide for an emergency patch or advisory related to this vulnerability.
- Implement robust endpoint detection and response (EDR) solutions to detect unusual activity that could indicate local privilege escalation attempts.
- Ensure all systems are running the latest security updates, even though the current exploit bypasses some recent patches.
- Restrict standard user privileges to the absolute minimum necessary to reduce the attack surface for local privilege escalation exploits.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.