# Microsoft Defender RoguePlanet Zero-Day Weaponized: SYSTEM-Level Exploit Works on Fully Patched Windows


A critical race condition vulnerability in Microsoft Defender is now actively exploited in the wild, granting attackers complete system control on updated Windows 11 and Windows 10 machines. Security researcher Chaotic Eclipse has released a working proof-of-concept after a public dispute with Microsoft over vulnerability disclosure practices, escalating an already contentious conflict into a full-scale security crisis.


## The Threat


RoguePlanet is a race condition vulnerability in Microsoft Defender that allows unauthenticated local attackers to escalate privileges to SYSTEM level—the highest privilege tier on Windows systems. Once exploited successfully, an attacker gains the ability to execute arbitrary code, install malware, disable security controls, or pivot to broader network compromise.


The vulnerability is particularly dangerous because:


  • It works on current systems: The exploit functions on Windows 11 and Windows 10 machines running June 2026 Patch Tuesday updates, meaning many organizations' "fully patched" environments remain vulnerable
  • Privilege escalation is near-guaranteed: While the exploit uses a race condition (inherently unreliable), independent security researchers have confirmed success rates from 100% on some machines to single-attempt success, making it practical for real-world attacks
  • Defender itself is the attack vector: Users cannot avoid this vulnerability by simply running antivirus software—the security product is weaponized against them

  • The researcher attributed the exploit's unreliability to the inherent nature of race conditions: "The exploit is a hit or miss...I have managed to get a 100% success rate on some machines while it struggled to work on others." However, the fact that it works consistently on some systems means attackers need only iterate or target systems where the race condition aligns favorably.


    ## Technical Details


    ### How RoguePlanet Exploits Defender


    The vulnerability centers on a path redirection attack within Defender's privileged execution context. While Microsoft has implemented defenses against this attack class, the researcher demonstrated those protections are insufficient.


    Attack flow:


    1. Attacker triggers a specific Defender operation that runs with SYSTEM privileges

    2. A race condition window opens during file system operations

    3. The attacker's malicious code redirects the file path to a location they control

    4. Defender executes the attacker's payload with SYSTEM privileges

    5. Attacker gains unrestricted system access


    ### Scope Limitations (For Now)


    The current PoC does not work on Windows Server because the exploit requires ISO image mounting—a capability available only to standard users on desktop Windows. However, Chaotic Eclipse has stated that Windows Server systems are equally vulnerable and that a Server-compatible exploit is feasible. This suggests a potentially broader attack surface once optimized.


    The researcher claimed to possess additional memory corruption vulnerabilities in Defender and other Windows components, suggesting this single exploit is merely the tip of a larger vulnerability class.


    ## Background and Context: The Microsoft-Researcher Dispute


    Understanding RoguePlanet requires examining the conflict between the researcher and Microsoft—one that appears to be driving uncoordinated, potentially retaliatory disclosures.


    ### The Researcher's Allegations


    Chaotic Eclipse (anonymous identity, operating under GitHub account "MSNightmare") has alleged:


  • Communication breakdown: Microsoft revoked the researcher's Microsoft Security Response Center (MSRC) access, the official channel for reporting vulnerabilities
  • Dismissal of reports: Microsoft allegedly dismissed vulnerability reports without proper technical review
  • Lack of compensation: No bug bounty or recognition was provided despite multiple critical findings
  • Reputational harm: The researcher claims Microsoft engaged in defamation and humiliation

  • In cryptographically signed posts on their Blogger page, Chaotic Eclipse expressed the personal toll: "Getting this PoC to work genuinely drained my soul, it severely degraded my mental and physical health."


    ### Microsoft's Response


    Microsoft has taken a hardline stance:


  • "Never justifiable": The company stated that public vulnerability disclosures without coordination are "never justifiable" and put customers at "unnecessary risk"
  • Platform deplatforming: Microsoft used its ownership of GitHub to take down the researcher's accounts, and GitLab reportedly followed suit
  • No legal action (stated): Microsoft claimed it has "no intention to pursue action against individuals conducting or publishing their security research," but stated it will work with law enforcement if "malicious activity" occurs
  • Recommitment to CVD: The company reiterated its commitment to Coordinated Vulnerability Disclosure (CVD) as "the foundation for protecting customers"

  • Security researcher Kevin Beaumont criticized Microsoft's approach, stating: "Microsoft is attempting to misuse its ownership of GitHub to protect only its own products, and misuse its extensive links to law enforcement by branding publishing information about vulnerabilities in its own products as criminal behaviour."


    ## Timeline of Recent Chaotic Eclipse Disclosures


    RoguePlanet is the fourth critical Microsoft Defender vulnerability disclosed by this researcher in recent months:


    | Vulnerability | CVE | Disclosure Date | Impact |

    |---|---|---|---|

    | BlueHammer | CVE-2026-33825 | Prior month | Privilege escalation |

    | UnDefend | CVE-2026-45498 | Prior month | Defender bypass |

    | RedSun | CVE-2026-41091 | Prior month | Memory corruption |

    | RoguePlanet | TBD | June 10, 2026 | SYSTEM privilege escalation (race condition) |


    Critically, all three prior vulnerabilities have already been exploited in the wild, demonstrating that threat actors are actively weaponizing these disclosures.


    ## Implications for Organizations


    ### Immediate Risk


    Organizations running Windows 11 or Windows 10 on standard user accounts are at elevated risk. The vulnerability does not require administrative privileges to trigger—a standard user can exploit it. This means:


  • Breach potential: An attacker gaining initial access through phishing, malware distribution, or supply chain compromise can immediately escalate to SYSTEM
  • Defense bypass: Any existing security tools or restrictions run by the user can be disabled post-exploitation
  • Lateral movement: SYSTEM access enables installing persistent backdoors, credential theft, and network reconnaissance

  • ### Detection Challenges


    Race condition exploits are inherently difficult to detect because:


  • They leave minimal forensic traces (timing-dependent, often transient artifacts)
  • Multiple failed attempts may appear as normal Defender operation
  • Successful exploitation may not generate obvious security events

  • Organizations relying on behavioral detection for Defender anomalies may experience false negatives.


    ## Recommendations


    ### For Organizations (Immediate)


    1. Monitor Defender logs for unusual process execution or privilege escalation attempts, particularly involving MpEngineStore.exe or other Defender system components

    2. Restrict standard user privileges where possible; organizations using privileged access workstations (PAWs) or application allowlisting have a significant advantage

    3. Prepare for emergency patching: When Microsoft releases a fix, treat it as critical and deploy within 48–72 hours

    4. Segment critical systems: Air-gap or network-isolate systems handling sensitive data until a patch is available


    ### For Security Teams


  • Hunt for exploitation attempts: Search telemetry for Defender-related exploitation signatures (Chaotic Eclipse will likely release updated variants)
  • Review incident timelines: If you experienced an unexplained SYSTEM-level compromise in late May or June 2026, this vulnerability may be the culprit
  • Engage threat intelligence: Correlate RoguePlanet with known threat actor infrastructure; APT groups typically adopt critical exploits within days of disclosure

  • ### For Microsoft


  • De-escalate the researcher conflict: Retaliatory account bans and legal pressure often drive further disclosures
  • Expedite patching: Provide emergency out-of-band patches rather than waiting for monthly patch cycles
  • Engage in good-faith dialogue: The researcher's grievances about dismissal and compensation may have legitimate technical and ethical dimensions worth addressing

  • ---


    ## HackWire Analysis


    The real story here isn't just RoguePlanet—it's the breakdown of the responsible disclosure ecosystem when researchers and vendors fail to operate in good faith.


    Chaotic Eclipse's allegations about dismissal, lack of compensation, and revoked access resonate with a growing cohort of independent security researchers who feel exploited by major tech companies. Whether or not every allegation is technically accurate, the pattern is clear: when researchers believe they are being stonewalled, some respond by going public—consequences be damned.


    Microsoft's response—platform deplatforming and public condemnation—may feel protective in the short term but historically backfires. The researcher responded by accelerating disclosures rather than withdrawing. The company's invocation of "never justifiable" disclosures rings hollow to security professionals who've watched months of dismissed vulnerability reports and revoked access channels.


    What's critical to recognize: RoguePlanet is not a one-off flaw; it's evidence of a pattern. Four critical Defender vulnerabilities in consecutive months, all in similar privilege escalation vectors, suggests either a systematic design flaw in Defender's architecture or a researcher who has identified an exploitable class of bugs and is methodically weaponizing them. The researcher's claim of possessing "a batch of memory corruption vulnerabilities in defender as well" implies the latter.


    Organizations should not treat this as a single patching exercise. Expect follow-on disclosures. The question is whether Microsoft can engineer faster security fixes and whether the industry's vulnerability disclosure process can prevent these escalations in the first place.


    Until that happens, assume Defender is a front-door key attackers can turn with the right timing and persistence.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)