Microsoft patches RoguePlanet Defender zero-day vulnerability

A major vulnerability in Microsoft’s Defender security software has been patched by the company after a researcher exposed it. The flaw, known as “RoguePlanet,” allowed attackers to gain high-level system privileges on fully patched Windows 10 and Windows 11 devices. This serious issue was disclosed by an independent security researcher using the handle Nightmare Eclipse, who also shared a proof-of-concept exploit code.

The RoguePlanet vulnerability is a type of bug that can be exploited through a “race condition,” which means it’s not always guaranteed to work. However, when it does, attackers can use it to spawn a command prompt with SYSTEM privileges, essentially giving them complete control over the affected system. This is particularly concerning because it affects even devices that are running the latest versions of Windows and have all the recommended security updates installed.

Nightmare Eclipse discovered RoguePlanet while working on multiple other Windows zero-day exploits, which they had disclosed earlier in the year. Some of these vulnerabilities targeted Microsoft Defender, while others aimed at BitLocker and Windows components. The researcher has been vocal about their concerns with Microsoft’s bug bounty program and vulnerability disclosure practices. In fact, Nightmare Eclipse claimed that Microsoft had previously removed their repositories on GitHub and GitLab, which hosted exploit codes.

Microsoft confirmed they were working on a patch for the RoguePlanet vulnerability on June 16 but did not acknowledge Nightmare Eclipse as the one who discovered it. However, after the researcher shared the proof-of-concept exploit code, the company released an update to the Microsoft Malware Protection Engine – a critical component of its security solutions and services. The new version, numbered 1.1.26060.3008, addresses the vulnerability identified by CVE-2026-50656.

This latest development highlights the ongoing cat-and-mouse game between cybersecurity researchers and software companies like Microsoft. While the researcher’s methods may be unorthodox, their disclosures have led to significant improvements in security patching. As the threat landscape continues to evolve, it’s essential for both individuals and organizations to stay vigilant and keep their systems up-to-date with the latest security patches.

To stay ahead of potential threats, users should regularly check for updates and ensure that all layers of their system are secure. This includes not only operating systems but also applications and network devices. By taking proactive measures, individuals can significantly reduce their risk of falling victim to attacks like RoguePlanet.


Source: Bleeping Computer — 2026-07-09