logo

Microsoft Defender zero-day RoguePlanet grants SYSTEM privileges

ID: c160a8c4-bee1-52af-8933-8ed061024031

STIX ID: report--c160a8c4-bee1-52af-8933-8ed061024031

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2026-06-10

Date Updated: 2026-06-11

...
...

On June 9, 2026, researcher/author "Nightmare Eclipse" published a proof-of-concept named RoguePlanet: an unpatched Windows zero-day local privilege escalation affecting Windows 10 and 11. RoguePlanet leverages Windows Defender remediation, a crafted ISO mounted without a drive letter, shadow copy detection, NTFS reparse points and oplock race conditions to overwrite C:\Windows\System32\wermgr.exe and trigger the \Microsoft\Windows\Windows Error Reporting\QueueReporting scheduled task to execute the payload with SYSTEM privileges; the report includes code analysis, IOCs (APIs, file paths, pipe, DLLs, embedded strings) and mitigations emphasizing application allowlisting and monitoring of atypical file movements into trusted Windows directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.