Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges
A newly disclosed zero-day vulnerability in Microsoft Defender, dubbed 'RoguePlanet', allows attackers to escalate privileges to SYSTEM level on fully patched Windows systems.

A security researcher known as Nightmare Eclipse has publicly released details and a proof-of-concept exploit for a zero-day vulnerability affecting Microsoft Defender, a critical component of Windows security. This flaw, named 'RoguePlanet', enables attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows 11 machines. The vulnerability is described as a race condition within Microsoft Defender, which, when successfully exploited, allows an attacker to spawn a command prompt with the highest level of system access.
The researcher claims the exploit works against both official and Canary builds of Windows 11, as well as Windows 10 systems that have received the June 2026 security updates. Cybersecurity firm ThreatLocker confirmed the exploit's viability, demonstrating its success against a fully patched Windows 11 system with KB5094126 installed. ThreatLocker CEO Danny Jenkins noted that organizations employing application allowlisting could effectively prevent the exploit from executing.
Originally, RoguePlanet was developed to exploit Microsoft Defender's handling of files on remote SMB shares, with the potential for remote code execution (RCE). The initial attack vector involved coercing a victim into opening a .vhd(x) file from a remote SMB server, which could lead to Defender overwriting its own files and resulting in RCE. Another potential RCE scenario involved tricking a user into opening an SMB share if symlink evaluation settings were enabled.
However, the researcher stated that Microsoft silently patched a key API ('mpengine!SysIO*') in mid-May, which blocked junction attacks and significantly altered the exploit's capabilities. This change forced a rewrite of RoguePlanet, and the researcher is currently uncertain if the vulnerability can still be leveraged for RCE or if it is now limited to local privilege escalation (LPE).
The public disclosure of RoguePlanet is part of an ongoing dispute between Nightmare Eclipse and Microsoft concerning the company's vulnerability disclosure and bug bounty programs. The researcher has previously released several other zero-day exploits targeting Microsoft products, including BlueHammer, RedSun, GreenPlasma, and YellowKey. Microsoft had previously addressed GreenPlasma and YellowKey in its June 2026 Patch Tuesday updates.
Microsoft has previously issued warnings about uncoordinated zero-day disclosures, with some interpreting their statements about working with law enforcement as a veiled threat towards researchers like Nightmare Eclipse. The researcher alleges that Microsoft has repeatedly targeted and removed their exploit repositories hosted on platforms like GitHub and GitLab, prompting the creation of a self-hosted code platform at projectnightcrawler.dev.
Microsoft has been contacted for comment regarding the RoguePlanet zero-day. The company's response to such disclosures, particularly when they involve researchers expressing grievances over disclosure practices, will be closely watched by the cybersecurity community. The potential for SYSTEM-level access via a Defender vulnerability underscores the critical importance of timely patching and robust endpoint security measures.
The newly released RoguePlanet exploit, detailed by researcher Nightmare Eclipse, targets a race condition vulnerability in Microsoft Windows Defender. This exploit allows unprivileged users to gain SYSTEM-level access on Windows 10 and 11, including systems patched with the June 2026 security updates. While the PoC does not currently work on Windows Server, the underlying flaw is believed to affect those systems as well.
The researcher Chaotic Eclipse, also known as Nightmare-Eclipse, has released a proof-of-concept exploit for the RoguePlanet zero-day vulnerability. This exploit, published on GitHub under the alias "MSNightmare," leverages a race condition to achieve SYSTEM-level access on updated Windows systems. The researcher claims a 100% success rate with this exploit, which was released shortly after the initial disclosure of the vulnerability.
This new report details the 'RoguePlanet' zero-day exploit, which targets a race condition within Windows Defender. Researcher 'Nightmare Eclipse' has released a proof-of-concept demonstrating how this vulnerability can be leveraged for local privilege escalation to SYSTEM-level execution via a command shell, even on patched systems.
This new article provides further technical details on the 'RoguePlanet' exploit, including its potential for BitLocker bypass and the specific challenges faced by the researcher in adapting it for Windows Server. It also highlights that the exploit has been tested against machines with the June 2026 patches installed, confirming its effectiveness even on updated systems.
The researcher known as Nightmare-Eclipse has released a new proof-of-concept exploit named RoguePlanet for a Windows Defender vulnerability. This exploit, which targets a race condition, can grant SYSTEM-level privileges if successful, and was released shortly after Microsoft's June Patch Tuesday updates. While the researcher states they are done with this specific bug, they have a history of publicly disclosing multiple Microsoft vulnerabilities following disputes over disclosure processes.
The researcher, known as Nightmare Eclipse, has also stated that this is their seventh Microsoft zero-day disclosure, and they have provided proof-of-concept exploit code for RoguePlanet. This follows a pattern of previous disclosures where exploit code was released before patches, leading to active exploitation of some flaws like RedSun, UnDefend, and BlueHammer.
Microsoft has now assigned CVE-2026-50656 to the RoguePlanet flaw and confirmed it is actively working on a patch, though it did not credit the original researcher, Nightmare Eclipse. The researcher, who disclosed the zero-day alongside a proof-of-concept exploit during June 2026 Patch Tuesday, stated the race condition can achieve SYSTEM privileges even when real-time protection is enabled. This disclosure is part of an ongoing dispute with Microsoft over its bug bounty practices, following previous leaks of several other Windows zero-days including BlueHammer, RedSun, and GreenPlasma.
Microsoft has now published an advisory acknowledging the public disclosure of the 'RoguePlanet' vulnerability, tracked as CVE-2026-50656 with a CVSS score of 7.8. The company confirmed it is working on a security update, though no patch timeline has been provided. The researcher noted that the proof-of-concept exploit works regardless of whether Defender's real-time protection is enabled, and may even function in passive mode.
Help Net Security reports that Microsoft formally acknowledged the zero-day and is developing a security update, though no patch timeline has been provided. The article further reveals that the exploit was released by an unidentified researcher, Nightmare Eclipse, who has published several other Microsoft zero-days since March 2026. Microsoft has not detected in-the-wild exploitation but rates the flaw 'Exploitation More Likely' per its Exploitability Index, and the researcher claims the PoC bypasses real-time protection and signature-based mitigations.
Microsoft has now formally assigned CVE-2026-50656 (CVSS 7.8) to the RoguePlanet zero-day and confirmed it is an elevation of privilege flaw in the Microsoft Malware Protection Engine. The company stated it is actively working on a security update to address the vulnerability. The researcher behind the exploit, Chaotic Eclipse, noted that the race-condition-based PoC works regardless of whether real-time protection is enabled, and even potentially in passive mode. RoguePlanet is the fourth Defender vulnerability disclosed by this researcher, following BlueHammer, UnDefend, and RedSun, all of which have been patched.
Microsoft has now officially acknowledged CVE-2026-50656, the RoguePlanet vulnerability, and confirmed it is actively developing a patch. The company rated exploitation as 'More Likely' on its Exploitability Index, though no in-the-wild exploitation has been observed yet. The researcher Nightmare Eclipse further revealed that the proof-of-concept works even when Defender's Real-Time Protection is disabled and may function in passive mode, while signature-based detection attempts have proven largely ineffective against minor modifications to the exploit.
Malwarebytes Labs reports that the exploit, dubbed RoguePlanet, relies on a race condition with success rates varying by machine, and that the same researcher previously submitted three other Microsoft Defender vulnerabilities (BlueHammer, UnDefend, RedSun) and four other Windows zero-days, all since patched. The article also notes that the exploit works regardless of whether active protection is enabled, and recommends users install the forthcoming security update, back up data, and avoid untrusted executables.