Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
A researcher released a Microsoft Defender zero-day that can spawn a SYSTEM-level command prompt on fully patched Windows 10 and 11 devices.
Intelligence analysis by GPT-5.4 Mini

Nightmare Eclipse says the new 'RoguePlanet' bug affects fully updated Windows systems and can sometimes yield SYSTEM privileges through a Defender race condition. ThreatLocker says it reproduced the issue, while Microsoft has not yet publicly commented.
A researcher found a Windows bug that can sometimes open a powerful command window as the boss account, called SYSTEM. It is like finding a spare key that can open the whole building, even after the locks were changed.
Analysis
What happened
A security researcher calling themselves Nightmare Eclipse published a new Microsoft Defender zero-day exploit named RoguePlanet. The article says it affects fully patched Windows 10 and Windows 11 systems and can spawn a command prompt with SYSTEM privileges when the race condition succeeds.
How it works
According to the researcher, the exploit targets Microsoft Defender and was tested against Windows 11 official and Canary builds, plus Windows 10 systems with June 2026 updates installed. Nightmare Eclipse says the issue is a race condition, which makes exploitation inconsistent: it may fail often, but it can also succeed repeatedly on some machines.
The researcher says RoguePlanet started as a remote code execution path involving Defender handling files hosted on remote SMB shares. In that earlier form, the attack required convincing a victim to open a .vhd(x) file on a remote SMB server. The researcher also says another scenario could have led to remote code execution if symlink evaluation settings were enabled. They claim Microsoft later hardened Defender in mid-May by patching an internal mpengine!SysIO* API, which blocked junction-based attacks and forced a rewrite of the exploit.
Why defenders care
ThreatLocker told BleepingComputer it reproduced the flaw against fully patched Windows 11 with KB5094126 installed. The company said application allowlisting can stop the exploit from running, which could provide a useful layer of defense.
The story also sits inside an ongoing conflict between the researcher and Microsoft over disclosure and bug bounty practices. The article says Nightmare Eclipse has already released several other Windows zero-days, including BlueHammer, RedSun, GreenPlasma, and YellowKey. Microsoft has previously warned about malicious activity causing real harm, and the researcher says earlier GitHub and GitLab repositories were removed, prompting a move to a self-hosted code site.
BleepingComputer says it contacted Microsoft for comment and will update the story if it gets a response.
Key points
- Nightmare Eclipse published a new Microsoft Defender zero-day called RoguePlanet.
- The article says it can spawn a command prompt with SYSTEM privileges on patched Windows 10 and 11 machines.
- ThreatLocker said it reproduced the flaw and confirmed it on fully patched Windows 11 with KB5094126.
- The researcher says Microsoft previously hardened Defender, forcing the exploit to be rewritten.
- Application allowlisting is presented as a possible mitigation layer.
If the exploit is quickly patched or blocked by defenses like application allowlisting, organizations can reduce the chance of real-world abuse. Public proof can also push Microsoft and security teams to harden Defender behavior faster.
The exploit works on fully patched Windows 10 and 11 systems, so defenders cannot assume normal updates are enough. Even if the race condition is unreliable, a successful run gives attackers SYSTEM privileges, which can lead to full compromise.



