New Microsoft Defender 'RoguePlanet' Exploit Grants Full System Access
A security researcher released a new zero-day exploit targeting Microsoft Defender on June 9, 2026, just hours after the company issued its monthly security updates. The exploit, dubbed “RoguePlanet,” reportedly affects fully patched Windows 10 and Windows 11 systems, allowing an attacker with low-level user access to gain the highest possible system privileges.
The vulnerability was disclosed by a researcher known as Nightmare Eclipse, who published a proof-of-concept exploit online. The flaw allows for local privilege escalation (LPE), meaning a malicious actor who has already gained an initial foothold on a device can elevate their access to “SYSTEM” level. This level of control effectively hands over the entire machine to the attacker, allowing them to install malware, steal sensitive data, disable security measures, and move laterally across a corporate network.
This incident is a critical reminder that even default, manufacturer-provided security tools are not infallible. For businesses, vulnerabilities in ubiquitous software represent a significant operational threat that extends well beyond the IT department.
The RoguePlanet exploit leverages a complex technique known as a “race condition” within Microsoft Defender. According to an analysis by cybersecurity firm ThreatLocker, the exploit tricks the security software during a file-handling process. The intended outcome is for the attacker’s malicious program to be written to the core Windows system directory, overwriting a legitimate file called `wermgr.exe`, the Windows Error Reporting executable. The exploit then uses the Windows Task Scheduler to trigger a standard error reporting task, which executes the now-replaced `wermgr.exe` file with SYSTEM privileges by default.
ThreatLocker confirmed it successfully reproduced the exploit on a fully patched Windows 11 machine, demonstrating its viability. Security researcher Will Dormann also noted on the social media platform Mastodon that the exploit “worked on the first attempt for me.” The original researcher, Nightmare Eclipse, stated that the exploit’s success can be a “hit or miss” depending on the machine’s configuration and timing, though they achieved a 100% success rate on some systems.
The release of RoguePlanet is the latest in a series of uncoordinated disclosures from the researcher, who also operates under the name Chaotic Eclipse. This appears to be part of an ongoing dispute with Microsoft over its vulnerability disclosure and bug bounty programs. Over the past several months, the same researcher has publicly released multiple zero-day flaws affecting Windows components, including exploits named BlueHammer, RedSun, GreenPlasma, and YellowKey.
The timing of the RoguePlanet disclosure is particularly pointed, coming on the same day as Microsoft’s June 2026 “Patch Tuesday.” In that update, Microsoft issued fixes for the GreenPlasma and YellowKey vulnerabilities, which had been previously disclosed by Nightmare Eclipse. The immediate release of a new, unpatched vulnerability suggests a direct response to Microsoft’s actions.
The release of an exploit like RoguePlanet underscores that cybersecurity is not just an IT department problem; it is a core business continuity and financial risk issue. For small and mid-sized companies that rely heavily on standard, built-in security software, a single vulnerability can be devastating. An attacker gaining the highest level of system access can bypass internal financial controls, access confidential client and employee data, and disrupt critical operations from payroll to supply chain management. In our experience, the fallout from such a breach often extends far beyond the initial technical fix, leading to direct financial losses, regulatory scrutiny, and long-term reputational damage. This is why a comprehensive approach to financial risk management must include a clear-eyed assessment of technology vulnerabilities. C&S Finance Group LLC works with businesses to build resilient operational frameworks that account for these exact threats, and you can learn more at csfinancegroup.com.
While Microsoft has not yet released a patch for RoguePlanet, security experts have outlined mitigation strategies. Danny Jenkins, CEO of ThreatLocker, told BleepingComputer that organizations using application allowlisting can prevent the exploit from executing. This security practice blocks any unsigned, untrusted, or unapproved programs from running, which would stop the malicious payload at the heart of the exploit. Experts also advise against relying on broad, path-based trust rules, such as automatically trusting any file located in the `C:\Windows\` directory. Because RoguePlanet specifically abuses this trust by placing its malicious file in that location, approval policies based on a file’s digital signature, publisher, or cryptographic hash provide significantly stronger protection.
With the exploit now public, the pressure is on Microsoft to address the vulnerability. Businesses should monitor for an out-of-band security update or expect a fix in the next scheduled Patch Tuesday. In the meantime, system administrators are advised to review and implement stricter application control policies to mitigate the immediate risk posed by this and similar privilege escalation attacks.