A newly disclosed zero day vulnerability, known as RoguePlanet, affects Microsoft Defender on fully patched Windows 10 and Windows 11 systems. The issue was publicly released in June 2026 by a researcher known as Nightmare Eclipse, who has published several Windows related exploits in recent months. RoguePlanet is a local privilege escalation vulnerability that allows a malicious actor with standard user access to obtain SYSTEM level privileges, representing the highest level of control on a Windows endpoint.
RoguePlanet vulnerability details
The vulnerability targets the Microsoft Defender anti-malware engine, specifically its file handling and remediation processes. Notably, testing indicates that the exploit remains effective even on systems that have received the latest June 2026 Patch Tuesday updates. This places organisations in a challenging position where traditional patching alone does not immediately mitigate risk.
RoguePlanet exploits a race condition within Microsoft Defender’s internal processing logic. This type of vulnerability, commonly referred to as a time-of-check to time-of-use condition, arises when the state of a resource changes between validation and execution.
In this case, Microsoft Defender performs privileged file operations as the SYSTEM user. An attacker can manipulate the timing of these operations to redirect Defender’s actions towards attacker-controlled locations, resulting in the execution of arbitrary code with SYSTEM privileges.
The exploit is described as unreliable in some environments due to the timing dependent nature of race condition vulnerabilities, however, researchers have reported consistent success on certain systems, demonstrating that it is viable in practice.
A proof of concept exploit has been made publicly available, increasing the likelihood of replication and adaptation by threat actors.
Impact of Microsoft Defender privilege escalation vulnerability
From a technical perspective, successful exploitation results in full SYSTEM level access. This allows attackers to execute arbitrary code, disable security controls, manipulate system files, and establish persistence mechanisms. Given that Microsoft Defender operates as a trusted security component, exploitation undermines the integrity of endpoint protection itself.
For organisations, the business impact can be significant. Privilege escalation vulnerabilities are commonly used as part of multi stage attack chains, enabling attackers to move from initial access to full compromise. This can facilitate data exfiltration, ransomware deployment, and lateral movement across networks.
Additional risk arises from the broader context of disclosures by Nightmare Eclipse. Recent vulnerabilities including BlueHammer, RedSun, GreenPlasma, and YellowKey demonstrate a pattern of targeting core Windows security mechanisms such as Defender and BitLocker. Several of these vulnerabilities have already been observed in active exploitation scenarios, highlighting the operational risk posed by publicly released proof of concept code.
Mitigation for RoguePlanet
At the time of writing, no comprehensive vendor patch for RoguePlanet has been confirmed across all reported variants, and it should be treated as an active zero-day exposure. Organisations should therefore adopt a layered mitigation strategy.
Application allowlisting has been identified as an effective defensive control, as it can prevent unauthorised binaries associated with exploitation from executing.
Monitoring for anomalous process creation, Defender related file activity, and unexpected privilege escalation events is strongly recommended. Security teams should also review configurations related to SMB shares and virtual disk handling, particularly where user interaction can be influenced.
Where available, organisations should apply all recent Microsoft security updates and monitor official advisories for further guidance.
How can Sentrium help?
Sentrium works with organisations to identify and reduce exposure to emerging vulnerabilities such as RoguePlanet through a combination of penetration testing and proactive security assessment.
Our penetration testing services focus on identifying privilege escalation pathways and validating the effectiveness of defensive controls, including endpoint protection and application allowlisting. We also support organisations in improving detection capability, ensuring that suspicious behaviour linked to exploitation attempts is identified early.
If you would like to understand how your environment may be impacted by this class of vulnerability, or need support assessing your exposure, get in touch to speak with one of our team.