discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges

A researcher released a Microsoft Defender zero-day that can spawn a SYSTEM-level command prompt on fully patched Windows 10 and 11 devices.

By Lawrence Abrams·Jun 9·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
Image: bleepingcomputer.com

Nightmare Eclipse says the new 'RoguePlanet' bug affects fully updated Windows systems and can sometimes yield SYSTEM privileges through a Defender race condition. ThreatLocker says it reproduced the issue, while Microsoft has not yet publicly commented.

Why it matters

This is a high-impact Windows privilege-escalation flaw because SYSTEM access is effectively full control of a machine. Even if exploitation is unreliable, a working proof of concept against patched systems raises the risk for defenders and incident responders.

A researcher found a Windows bug that can sometimes open a powerful command window as the boss account, called SYSTEM. It is like finding a spare key that can open the whole building, even after the locks were changed.

Analysis

What happened

A security researcher calling themselves Nightmare Eclipse published a new Microsoft Defender zero-day exploit named RoguePlanet. The article says it affects fully patched Windows 10 and Windows 11 systems and can spawn a command prompt with SYSTEM privileges when the race condition succeeds.

How it works

According to the researcher, the exploit targets Microsoft Defender and was tested against Windows 11 official and Canary builds, plus Windows 10 systems with June 2026 updates installed. Nightmare Eclipse says the issue is a race condition, which makes exploitation inconsistent: it may fail often, but it can also succeed repeatedly on some machines.

The researcher says RoguePlanet started as a remote code execution path involving Defender handling files hosted on remote SMB shares. In that earlier form, the attack required convincing a victim to open a .vhd(x) file on a remote SMB server. The researcher also says another scenario could have led to remote code execution if symlink evaluation settings were enabled. They claim Microsoft later hardened Defender in mid-May by patching an internal mpengine!SysIO* API, which blocked junction-based attacks and forced a rewrite of the exploit.

Why defenders care

ThreatLocker told BleepingComputer it reproduced the flaw against fully patched Windows 11 with KB5094126 installed. The company said application allowlisting can stop the exploit from running, which could provide a useful layer of defense.

The story also sits inside an ongoing conflict between the researcher and Microsoft over disclosure and bug bounty practices. The article says Nightmare Eclipse has already released several other Windows zero-days, including BlueHammer, RedSun, GreenPlasma, and YellowKey. Microsoft has previously warned about malicious activity causing real harm, and the researcher says earlier GitHub and GitLab repositories were removed, prompting a move to a self-hosted code site.

BleepingComputer says it contacted Microsoft for comment and will update the story if it gets a response.

Key points

  • Nightmare Eclipse published a new Microsoft Defender zero-day called RoguePlanet.
  • The article says it can spawn a command prompt with SYSTEM privileges on patched Windows 10 and 11 machines.
  • ThreatLocker said it reproduced the flaw and confirmed it on fully patched Windows 11 with KB5094126.
  • The researcher says Microsoft previously hardened Defender, forcing the exploit to be rewritten.
  • Application allowlisting is presented as a possible mitigation layer.
The Upside

If the exploit is quickly patched or blocked by defenses like application allowlisting, organizations can reduce the chance of real-world abuse. Public proof can also push Microsoft and security teams to harden Defender behavior faster.

The Downside

The exploit works on fully patched Windows 10 and 11 systems, so defenders cannot assume normal updates are enough. Even if the race condition is unreliable, a successful run gives attackers SYSTEM privileges, which can lead to full compromise.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechmicrosoftwindowszero-day

Author

Lawrence Abrams

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 9, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechmicrosoftwindowszero-day

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…