logo

New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers

ID: 3f94877f-a4b3-52e1-9e6f-d7d991e6ba54

STIX ID: report--3f94877f-a4b3-52e1-9e6f-d7d991e6ba54

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Guru Baran

...
...

**Executive summary:** A public proof-of-concept called RoguePlanet, released by researcher "Nightmare Eclipse," exploits a TOCTOU race condition in Microsoft Defender to spawn a SYSTEM-level shell on fully patched Windows 10 and 11 systems; the author has published multiple Defender-targeting exploits and prior tooling has been observed in live intrusions, increasing the urgency for organizations to monitor for an emergency patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.