Windows Defender Zero-Day “RoguePlanet” Lets Attackers Gain SYSTEM Privileges
ID: b6e3b0a0-ea5d-5f0b-97b3-a361b9946e43
STIX ID: report--b6e3b0a0-ea5d-5f0b-97b3-a361b9946e43
Feed Name: GBHackers
Threat Score
A newly disclosed zero-day, dubbed “RoguePlanet,” affects Microsoft Defender on Windows 10 and Windows 11 and allows privilege escalation to NT AUTHORITY\SYSTEM by exploiting a race condition in Defender’s file handling (PoC published). The PoC leverages ISO mounting and timing of file operations; although exploitation reliability varies, the researcher reports near-100% success on some systems, and public availability of the exploit raises significant risk until a patch is issued.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
