Windows zero-click vulnerability CVE-2026-32202 leaking NTLM credentials via malicious LNK file

Microsoft’s Record Patch Tuesday Upstaged Within Hours by New Defender Zero-Day

Microsoft’s June Patch Tuesday addressed about 200 vulnerabilities, but the emergence of a new exploit, RoguePlanet, highlights ongoing security concerns with Microsoft Defender.

Microsoft shipped its largest-ever Patch Tuesday this week, fixing roughly 200 vulnerabilities across Windows and other products. But the size of the release was quickly overshadowed by a new Microsoft Defender exploit that was not covered by the update.

Within hours of the June Patch Tuesday release, the pseudonymous researcher known as Nightmare Eclipse, also called Chaotic Eclipse, published a proof-of-concept exploit for a new apparent zero-day dubbed “RoguePlanet.”

The exploit abuses a race condition in Microsoft Defender. When successful, it can spawn a command shell with SYSTEM-level privileges, giving an attacker deep control of the machine.

The PoC runs on fully-up-to-date machines. The researcher tested it on Windows 10 and 11 with this month’s patches already installed. Security firm ThreatLocker says it independently reproduced the exploit — so this is real, not theoretical — though its allowlisting blocked the attack by default, which is the practical defense while no patch exists.

Security firm ThreatLocker said it independently reproduced the exploit on a fully patched Windows 11 system. ThreatLocker also said application allowlisting can stop the exploit from executing, which makes allowlisting one of the clearest practical defenses while no Microsoft patch is available.

The current exploit should still be understood as local privilege escalation, not a confirmed remote takeover path. An attacker would need some way to run code or otherwise get a foothold on the target system first. From there, RoguePlanet could turn limited access into SYSTEM-level control.

The release is part of a continuing public-disclosure campaign tied to a dispute between Nightmare Eclipse and Microsoft over vulnerability handling and bug bounty practices. Rapid7 said the researcher has drawn attention in recent weeks by publishing details of multiple Microsoft vulnerabilities, including Defender elevation-of-privilege bugs and a Secure Boot disk encryption bypass.

Microsoft has said several earlier disclosures were not coordinated and put customers at unnecessary risk. The company also said it would work with law enforcement when people engage in malicious activity that causes real harm to customers. Microsoft later clarified that it has no intention of pursuing action against security researchers merely for conducting or publishing security research.

RoguePlanet appears to be at least the seventh flaw in the series. Microsoft patched two earlier Nightmare Eclipse-related issues, GreenPlasma and YellowKey, as part of the June Patch Tuesday release. Earlier flaws in the same broader campaign, including BlueHammer, RedSun and UnDefend, have also received CVEs or Microsoft fixes.

Nightmare Eclipse says RoguePlanet originally had a remote code execution path involving Microsoft Defender’s handling of files on remote SMB shares. The researcher claims a Defender hardening change Microsoft pushed in May closed off that remote path, leaving the current public version as local privilege escalation.

As of publication, RoguePlanet does not appear to have a CVE or Microsoft advisory. Defenders should monitor Microsoft’s Security Update Guide and Defender release notes for an out-of-band fix or Defender platform update.

Total
0
Shares
Previous Article
Illustration of a lion on a leather leash, symbolizing Anthropic's Claude Fable 5 restraining its Mythos-class AI.

Anthropic Puts Mythos on a Leash

Next Article
CISA cybersecurity seal on a circuit-board background representing a federal warning about an actively exploited Oracle WebLogic vulnerability.

CISA’s Patch Ultimatum: Fix the Riskiest Bugs in 3 Days

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading