Microsoft Reins in RoguePlanet Zero-Day Threat

Microsoft has tackled another zero-day vulnerability published by a disgruntled security researcher, issuing an out-of-band patch for RoguePlanet, an elevation-of-privilege flaw in Windows Defender. The high-severity vulnerability could have allowed an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, effectively granting them complete control over the device.

The patch for RoguePlanet is included in the Microsoft Malware Protection Engine version 1.1.26060.3008. However, it’s worth noting that Windows systems without Microsoft Defender enabled are not vulnerable to this exploit. According to Microsoft’s advisory, the attack complexity for the vulnerability is low, and exploitation is “more likely.” This suggests that malicious actors may have already started exploiting RoguePlanet in the wild.

The story behind RoguePlanet is a complex one. The anonymous security researcher known as Nightmare-Eclipse has been at odds with Microsoft for several months. In April, they published an exploit for another privilege-escalation flaw in Windows Defender, dubbed BlueHammer. Since then, Nightmare-Eclipse has continued to publish zero-day exploits, including RoguePlanet, as a form of revenge against Microsoft. This public feud has raised concerns about the potential risks posed by these exploits.

SOCRadar, a cybersecurity research firm, notes that RoguePlanet is not remotely exploitable on its own but can be highly valuable after an attacker gains local code execution as a standard user. As a second-stage tool, RoguePlanet could allow threat actors to tamper with security products and telemetry, dump credentials for lateral movement, and establish persistence through scheduled tasks and other techniques.

The fact that Microsoft issued this emergency update shortly before the July Patch Tuesday release is unusual but likely due to increased urgency around the flaw. According to Ensar Seker, SOCRadar’s chief information security officer, Nightmare-Eclipse’s repeated publication of detailed technical analyses and proof-of-concept exploits has reduced the amount of time defenders have before attackers can begin weaponizing the research.

While it remains unclear whether RoguePlanet has been exploited in the wild, this incident highlights the importance of staying up-to-date with security patches. Even if a vulnerability hasn’t been publicly exploited yet, its release can create a sense of urgency among malicious actors to exploit it quickly. As a result, users should ensure their Windows systems are patched as soon as possible and remain vigilant about potential threats in the coming weeks.

In light of this incident, it’s essential for organizations to implement robust security measures, including regular patching, monitoring, and incident response planning. By staying informed and proactive, businesses can minimize the risks associated with zero-day vulnerabilities like RoguePlanet and protect themselves from potential attacks.


Source: Dark Reading — 2026-07-09