# Microsoft Defender RoguePlanet Zero-Day Allows Attackers to Spawn SYSTEM Privileges on Windows


Researcher Nightmare Eclipse releases new Windows privilege escalation exploit hours after Microsoft Patch Tuesday, reigniting dispute over disclosure practices and vulnerability coordination.


## The Threat


A security researcher operating under the pseudonym Nightmare Eclipse has released a proof-of-concept exploit for a previously undisclosed Microsoft Defender zero-day vulnerability dubbed "RoguePlanet." The flaw enables attackers to escalate privileges and spawn a Windows command prompt with SYSTEM-level access on fully patched Windows 10 and Windows 11 machines.


The exploit targets a race condition in how Microsoft Defender processes files, allowing attackers who gain initial access to a system to elevate their permissions to the highest privilege level available on Windows. The release came hours after Microsoft addressed two other flaws from the same researcher during its June 2026 Patch Tuesday security update.


According to Nightmare Eclipse's disclosure documentation, the vulnerability operates as a local privilege escalation (LPE) attack that doesn't require user interaction beyond the attacker's initial foothold on the target system. However, the exploit exhibits variable reliability across different machines.


## Technical Details


### How RoguePlanet Works


RoguePlanet exploits a race condition in Microsoft Defender's file handling logic. The researcher describes the vulnerability as stemming from how the antivirus engine processes virtual disk files (VHD/VHDX) and related file operations, creating a window where an attacker can manipulate the system's behavior.


"The exploit is a race condition, so it's a hit or miss," Nightmare Eclipse explained in their repository documentation. "I have managed to get a 100% success rate on some machines while it struggled to work on others."


The variable success rate reflects the inherent nature of race conditions—timing-dependent vulnerabilities where success depends on executing operations in a specific sequence at precise moments. This unpredictability has both advantages and disadvantages:


| Aspect | Impact |

|--------|--------|

| Reliability | Reported 100% on some systems; inconsistent on others |

| Detectability | Multiple execution attempts needed may trigger behavioral alerts |

| Exploitation Window | Narrow timing window requires precise conditions |

| Mitigation Complexity | Harder to patch than straightforward logic flaws |


### Evolution from RCE Concept


The current RoguePlanet exploit represents a downgrade in severity from the researcher's original findings. Nightmare Eclipse initially developed the vulnerability as a remote code execution (RCE) attack that could be triggered by coercing a victim to open a malicious VHD file on a remote SMB (Server Message Block) share.


The original attack flow involved:

  • Defender attempting to scan files on the remote share
  • Defender overwriting its own components during the scan process
  • This overwriting resulting in arbitrary code execution with Defender's privileges

  • Microsoft appears to have partially addressed the RCE vector by hardening the mpengine!SysIO* API functions in mid-May 2026, blocking junction-based attacks that enabled the SMB share scenario. This forced the researcher to redesign the exploit, limiting it to local privilege escalation only.


    "Rewriting RoguePlanet to make it functional again drained my soul," the researcher wrote, suggesting frustration with the incremental patching approach. The current version no longer achieves RCE via SMB coercion, though the researcher indicates uncertainty about whether other RCE pathways remain.


    ### Verification and Confirmation


    The exploit's validity was confirmed by cybersecurity firm ThreatLocker, which independently reproduced the vulnerability in their lab environment. Testing verified successful exploitation on fully patched Windows 11 systems with KB5094126 installed, demonstrating the flaw persists despite Microsoft's latest security updates.


    "Our initial analysis confirms that the RoguePlanet exploit is viable and performs as described," said Danny Jenkins, CEO of ThreatLocker, in a statement to BleepingComputer. "Organizations using application allowlisting can prevent the exploit from executing, providing an effective layer of protection against this attack."


    ## Background and Context


    ### The Researcher's Disclosure Dispute


    Nightmare Eclipse's release of RoguePlanet represents the latest chapter in an ongoing conflict between the independent researcher and Microsoft over vulnerability disclosure practices and bug bounty compensation.


    Over the past several months, the researcher has publicly released multiple Windows zero-days:


  • BlueHammer — Windows privilege escalation vulnerability
  • RedSun — Windows component flaw
  • GreenPlasma — BitLocker-related vulnerability
  • YellowKey — Windows security component flaw
  • RoguePlanet — Microsoft Defender race condition

  • Two of these flaws (GreenPlasma and YellowKey) were addressed in the June 2026 Patch Tuesday release. The staggered disclosure of multiple zero-days suggests the researcher is deliberately maintaining a queue of exploits to release over time.


    ### Repository Removals and Escalation


    The researcher claims Microsoft has actively targeted and removed code repositories hosting the exploits from both GitHub and GitLab platforms, effectively suppressing public access to proof-of-concept code. In response, Nightmare Eclipse established a self-hosted Git platform at projectnightcrawler.dev to distribute exploits beyond Microsoft's reach.


    This escalation mirrors past conflicts in the security research community, where vendors have attempted to suppress or delay disclosure of security flaws. Microsoft's actions have prompted criticism from segments of the cybersecurity community, particularly regarding the company's approach to coordinated vulnerability disclosure.


    ### Microsoft's Legal Threats


    Microsoft has responded to the researcher's activities with public warnings that the company "will work with law enforcement when people engage in malicious activity causing real harm to our customers." Many in the security community interpreted this as a direct threat of legal prosecution against Nightmare Eclipse.


    The messaging has intensified tensions, with some analysts questioning whether Microsoft's aggressive posture might be driving the researcher toward increasingly public and immediate disclosures rather than encouraging traditional responsible disclosure channels.


    ## Implications for Organizations


    ### Affected Systems


    Any organization running Windows 10 or Windows 11 with Microsoft Defender enabled is potentially vulnerable to this attack, regardless of patch level. The exploit succeeds against:


  • Windows 11 (Official and Canary builds)
  • Windows 10 with June 2026 security updates
  • Systems with all critical patches applied

  • The vulnerability requires initial system access, making it a post-compromise privilege escalation risk rather than an entry-vector vulnerability.


    ### Attack Scenarios


    Organizations should consider these realistic attack scenarios:


    1. Lateral movement escalation — An attacker gaining user-level access through phishing or another vulnerability could escalate to SYSTEM privileges

    2. Malware privilege elevation — Commodity malware could be modified to exploit this flaw

    3. Supply chain persistence — Attackers with compromise of a vendor or software update could escalate privileges system-wide

    4. Insider threats — Malicious insiders with user access could elevate to administrative control


    ## Detection and Mitigation


    ### Immediate Protective Measures


    Organizations can implement several controls to reduce RoguePlanet exploitation risk:


    Application Allowlisting — ThreatLocker confirmed that application allowlisting (also called "application whitelisting") effectively prevents RoguePlanet exploitation by restricting what processes can execute. Organizations using solutions like AppLocker or third-party allowlisting can enforce policies that block unauthorized command prompt spawning.


    Windows Defender Application Control (WDAC) — Microsoft's native code integrity feature can restrict execution to approved binaries, preventing the exploitation payload from running.


    Privileged Access Management (PAM) — Restricting which accounts can access sensitive systems and monitoring for unexpected privilege escalation attempts adds defensive layers.


    Behavioral Detection — Endpoint Detection and Response (EDR) solutions should alert on:

  • Unexpected SYSTEM-level process spawning
  • Defender component modifications
  • Race condition pattern detection (multiple rapid file operations)

  • ### Monitoring and Response


    Organizations should implement:

  • Enhanced monitoring of Defender operations and file access patterns
  • Behavioral alerts for privilege escalation attempts
  • Audit logging of SYSTEM-level process creation
  • Regular privilege access reviews to detect exploitation

  • ## HackWire Analysis


    Why This Timing Matters — And What It Reveals About Microsoft's Vulnerability Response


    The release of RoguePlanet within hours of Patch Tuesday is strategically significant and reveals fundamental tensions in how large vendors and independent researchers interact around zero-day disclosure. Nightmare Eclipse appears to be following a deliberate strategy: maintain a queue of exploits and release them when Microsoft publishes patches for related flaws, maximizing visibility and signaling that the researcher views Microsoft's patching cadence as inadequate.


    This is pattern recognition at scale. The researcher has released five distinct Windows zero-days in recent months—not all simultaneously, but in a distributed manner that keeps Microsoft in constant reaction mode. Each release forces the vendor into a crisis response cycle, generates media attention, and reinforces the researcher's implicit message: Microsoft's current vulnerability disclosure and bounty program is not sufficient incentive to submit flaws privately.


    The most significant hidden risk here isn't the technical severity of RoguePlanet itself—privilege escalation flaws are serious but require prior access. The real danger is the erosion of trust in coordinated disclosure. When researchers stop reporting vulnerabilities privately, exploit release timelines compress. Nation-state actors and criminal groups may not have months to wait; they'll grab these exploits immediately upon release.


    Microsoft's legal threats and repository takedowns are driving the opposite behavior they intend. Rather than compelling Nightmare Eclipse to engage quietly, these actions incentivized the creation of a self-hosted distribution platform—making suppression impossible and encouraging accelerated, public release cycles.


    For defenders, the concrete implication is clear: assume patches will lag exploit availability. Organizations must shift from reactive "wait for patch Tuesday" models to proactive assumption of compromise. Assume SYSTEM-level access is possible on Defender machines before patches arrive. Application allowlisting and behavioral detection aren't nice-to-haves—they become prerequisites.


    The researcher's point is worth hearing: the current vulnerability ecosystem may genuinely be broken when independent researchers feel driven to public escalation rather than private collaboration.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)