Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Home/CyberSecurity News/Critical Windows Defender Zero-Day Lets Attackers Gain SYSTEM Access
CyberSecurity News

Critical Windows Defender Zero-Day Lets Attackers Gain SYSTEM Access

Key Takeaways A new zero-day exploit, “RoguePlanet,” targeting Microsoft Windows Defender has been publicly released by security researcher Nightmare Eclipse. The exploit leverages a race...

Sarah simpson
Sarah simpson
June 10, 2026 3 Min Read
49 0

Key Takeaways

  • A new zero-day exploit, “RoguePlanet,” targeting Microsoft Windows Defender has been publicly released by security researcher Nightmare Eclipse.
  • The exploit leverages a race condition to achieve SYSTEM-level privileges on Windows 10 and 11 systems, including those fully patched as of June 2026.
  • This vulnerability allows an unprivileged local user to gain the highest possible access on a compromised machine.
  • Microsoft has not yet assigned a CVE or released a patch for RoguePlanet, despite the active exploitation of previous tools from the same researcher.

New Windows Defender Zero-Day “RoguePlanet” Grants SYSTEM Access

A critical zero-day vulnerability in Microsoft Windows Defender has been publicly exposed with the release of a new proof-of-concept (PoC) exploit named RoguePlanet. Developed by security researcher Nightmare Eclipse, also known as Chaotic Eclipse and Dead Eclipse, the exploit targets a previously undisclosed race condition within Microsoft’s antivirus software.

Table Of Content

  • Key Takeaways
  • New Windows Defender Zero-Day “RoguePlanet” Grants SYSTEM Access
  • Understanding the RoguePlanet Exploit
  • A Pattern of Disclosures and Real-World Impact
  • What You Should Do

Successful execution of RoguePlanet results in the spawning of a command shell operating with SYSTEM-level privileges, effectively granting an attacker complete control over a compromised Windows system. The exploit’s public release on GitHub coincides with Patch Tuesday, June 10, 2026, intensifying concerns amid a series of recent disclosures targeting Defender.

Understanding the RoguePlanet Exploit

RoguePlanet functions as a local privilege escalation (LPE) exploit, exploiting a race condition inherent in Microsoft Defender’s internal processes. An unprivileged local user can leverage this flaw to redirect a file operation performed by Defender, which typically runs with SYSTEM privileges. This redirection allows the attacker to execute their own code at the highest privilege level available on the system.

The researcher has confirmed RoguePlanet’s efficacy on fully updated Windows 10 and Windows 11 systems, encompassing both stable releases and Canary Insider Preview channels, even with the June 2026 patches applied. While Windows Server installations are also deemed vulnerable to the underlying flaw, the current PoC is not directly functional in those environments due to a prerequisite involving ISO image mounting, which standard users cannot perform on servers.

The core vulnerability is a Time-of-Check to Time-of-Use (TOCTOU) race condition. This class of vulnerability was previously exploited by Nightmare Eclipse in the BlueHammer exploit (CVE-2026-33825), which carried a CVSS score of 7.8 (High) and was addressed by Microsoft in April 2026. In that prior instance, Defender’s file remediation engine performed privileged write operations without adequate validation of file paths, allowing attackers to introduce NTFS junction points that rerouted Defender’s SYSTEM-level writes into the C:WindowsSystem32 directory.

RoguePlanet employs a similar path-redirection technique, indicating that Microsoft’s efforts to mitigate this specific class of attack within Defender may still be incomplete.

A Pattern of Disclosures and Real-World Impact

RoguePlanet is the latest in a series of zero-day disclosures by Nightmare Eclipse, who has reportedly released at least seven Defender-related exploits since early April 2026. This extensive list includes BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma.

The cybersecurity community widely perceives this ongoing campaign as a retaliatory measure following disagreements with Microsoft concerning responsible disclosure practices and account terminations. Notably, researchers at Huntress have already observed real-world intrusions leveraging earlier tools from this researcher, with BlueHammer, RedSun, and the Defender-disruption tool UnDefend documented in active attack chains.

The success rate of RoguePlanet can fluctuate across different environments. While the researcher reports a 100% success rate on some machines, the exploit’s effectiveness may vary on others, a common characteristic of race condition vulnerabilities. Although the current exploit does not function on Windows Server, all Server versions are believed to be susceptible to the underlying flaw, requiring a modified attack vector.

As of this publication, Microsoft has not yet issued a CVE identifier or a public advisory for RoguePlanet. Given the documented active exploitation of previous tools developed by Nightmare Eclipse, organizations utilizing Windows 10 or Windows 11 endpoints should prioritize this disclosure and closely monitor Microsoft’s Security Update Guide for an expedited patch.

What You Should Do

  • Monitor Microsoft’s Security Update Guide for an emergency patch or advisory related to this vulnerability.
  • Implement robust endpoint detection and response (EDR) solutions to detect unusual activity that could indicate local privilege escalation attempts.
  • Ensure all systems are running the latest security updates, even though the current exploit bypasses some recent patches.
  • Restrict standard user privileges to the absolute minimum necessary to reduce the attack surface for local privilege escalation exploits.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

MagicAd Android Malware Bypasses Restrictions, Floods Devices with Ads

Next Post

Anthropic Debuts Claude Fable 5, First Mythos-Class AI Model

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us