A newly disclosed Windows zero-day vulnerability, dubbed RoguePlanet, has been made public by security researcher Nightmare Eclipse, escalating a long-standing feud with Microsoft over vulnerability disclosure practices. The exploit code leverages a race condition issue in Microsoft Defender, potentially allowing attackers to gain SYSTEM-level privileges, although the success rate is less than 100%. This latest revelation underscores the ongoing tensions between Eclipse and Microsoft, with the researcher having released several unpatched Windows vulnerabilities in recent months. The RoguePlanet flaw poses a significant risk to Windows users, as it can be exploited before a patch is available1. As a result, the window for patching is rapidly shrinking, making it essential for users to assess their exposure to this vulnerability immediately. The disclosure of this zero-day flaw highlights the need for prompt action to mitigate potential attacks, making it crucial for practitioners to evaluate their systems' vulnerability to RoguePlanet.
Microsoft feud escalates as researcher drops new Windows zero-day
⚠️ Critical Alert
Why This Matters
Zero-day activity targeting Microsoft means patching windows are already closing — assess your exposure immediately.
References
- CSO Online. (2026, June 10). Microsoft feud escalates as researcher drops new Windows zero-day. CSO Online. https://www.csoonline.com/article/4183487/microsoft-feud-escalates-as-researcher-drops-new-windows-zero-day.html
Original Source
CSO Online
Read original →