Microsoft-Threatened Researcher Drops Seventh Windows Zero-Day
Security researcher Chaotic Eclipse has publicly released "RoguePlanet," a seventh Windows zero-day exploit, just hours after Microsoft's record-breaking June Patch Tuesday. This vulnerability grants SYSTEM privileges on fully patched Windows 10 and 11 systems, deepening a dispute with Microsoft over previous disclosures. The exploit leverages a race condition in Windows Defender.

Security researcher "Chaotic Eclipse," who previously faced threats from Microsoft, has publicly released a seventh Windows zero-day exploit, dubbed "RoguePlanet." This disclosure came merely hours after the tech giant’s record-setting June Patch Tuesday, reigniting an escalating and contentious public dispute over vulnerability reporting.
The newly revealed RoguePlanet vulnerability grants attackers SYSTEM-level privileges on fully updated Windows 10 and 11 systems. This means that even machines that applied Microsoft’s latest patches remain susceptible to this particular exploit, underscoring a significant challenge in maintaining system security.
Unpacking the RoguePlanet Exploit
RoguePlanet specifically leverages a race condition within Windows Defender's internal processing logic, identified as a Time-of-Check to Time-of-Use (TOCTOU) flaw. This allows an unprivileged user to maliciously redirect a file operation, typically performed by Defender with SYSTEM privileges, to execute attacker-controlled code at the highest possible access level. The researcher noted that while the exploit can be "hit or miss," they achieved a 100% success rate on some test machines.
The viability of RoguePlanet has been independently confirmed by security firm ThreatLocker. Danny Jenkins, CEO of ThreatLocker, stated, "Our initial analysis confirms that the RoguePlanet exploit is viable and performs as described." He also highlighted that implementing application allowlisting could prevent the exploit from successfully executing, offering a potential mitigation strategy.
A Deepening Feud with Microsoft
This public release marks the latest escalation in a bitter conflict between Chaotic Eclipse and Microsoft. The researcher claims these disclosures are in direct retaliation for Microsoft's aggressive handling of their previous vulnerability reports. This alleged behavior includes threats of criminal prosecution, the invocation of Microsoft's Digital Crimes Unit, and the revocation of Chaotic Eclipse’s access to their Microsoft Security Response Center (MSRC) account. Furthermore, the researcher stated that Microsoft had earlier proof-of-concept exploits removed from both GitHub and GitLab repositories.
Chaotic Eclipse has openly expressed deep frustration with Microsoft's approach, characterizing their actions as "childish games" and accusing the corporation of deliberately causing them distress throughout the disclosure process.
Patch Tuesday's Ironic Aftermath
The timing of RoguePlanet's release is particularly poignant, coinciding almost immediately after Microsoft's largest-ever June Patch Tuesday. This historic update cycle addressed an unprecedented 200 vulnerabilities, including 33 critical flaws and three zero-days that were already publicly known. However, RoguePlanet's emergence highlights a critical gap: despite this monumental patching effort, fully updated systems are immediately vulnerable to this new threat.
Of the seven zero-days disclosed by Chaotic Eclipse—BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, MiniPlasma, and now RoguePlanet—only GreenPlasma and YellowKey were addressed in the recent Patch Tuesday. This leaves five other vulnerabilities previously reported by the researcher still unpatched, further fueling the ongoing dispute and the immediate risk to Windows users.
The Accelerating Cybersecurity Landscape
This incident underscores a broader trend in cybersecurity: the accelerating pace of vulnerability discovery. Industry analysts suggest that advancements in tools like AI-assisted code auditing are enabling researchers to identify flaws at an unprecedented rate. This creates a challenging environment where even the most comprehensive patching efforts struggle to keep pace with newly emerging threats, effectively placing defenders in a continuous uphill battle against an evolving landscape of vulnerabilities.
With RoguePlanet now publicly detailed, the immediate risk to Windows users persists, emphasizing the urgent need for a multi-layered defense strategy beyond traditional patching. The ongoing saga between Chaotic Eclipse and Microsoft continues to illuminate the complex dynamics of responsible disclosure and corporate responses in the critical cybersecurity domain.
FAQ
Q: What is RoguePlanet and what kind of vulnerability does it exploit?
A: RoguePlanet is the seventh Windows zero-day exploit released by security researcher Chaotic Eclipse. It exploits a race condition, specifically a Time-of-Check to Time-of-Use (TOCTOU) vulnerability, within Windows Defender's internal processing logic, allowing an unprivileged user to gain SYSTEM privileges.
Q: Why did Chaotic Eclipse release this zero-day publicly?
A: Chaotic Eclipse stated that the public disclosures are in retaliation for Microsoft's handling of the vulnerability reporting process. This includes Microsoft allegedly threatening criminal prosecution, invoking its Digital Crimes Unit, revoking the researcher's MSRC account access, and removing earlier exploit repositories from GitHub and GitLab.
Q: How does RoguePlanet impact users who have applied the latest Patch Tuesday updates?
A: RoguePlanet affects fully patched Windows 10 and 11 machines, meaning that even systems updated with Microsoft's record-setting June Patch Tuesday remain vulnerable to this specific zero-day. While Patch Tuesday addressed many issues, RoguePlanet was not among them, and five of Chaotic Eclipse's seven disclosed zero-days remain unpatched.
Related articles
Home Chef Unveils Major Promo Codes for June 2026
Home Chef rolls out significant June 2026 promo codes, offering new customers up to 75% off their first box and 18 free meals. Special discounts are also available for families and essential workers, enhancing access to its popular, user-friendly meal kits.
100 Cyber Experts: Fable 5 Ban Hurts Defenders More Than Hackers
Nearly 100 prominent cybersecurity experts have signed an open letter condemning the US government's ban on Anthropic's Fable 5 and Mythos 5 AI models. They argue the move disarms defenders, creates market uncertainty, and risks America's AI leadership without justifiable cause, potentially benefiting adversaries more than protecting national security.
Sakana AI Launches 'Ultra Deep Research' Agent: 100+ Page Reports in
Sakana AI has launched Marlin, an "ultra deep research" agent designed for enterprise clients. Operating as a "Virtual CSO," Marlin conducts self-governing reasoning for up to eight hours to deliver comprehensive, 100+ page strategy reports. Powered by Adaptive Branching Monte Carlo Tree Search (AB-MCTS) and a multi-LLM architecture, it focuses on deep, vetted analysis over quick generation, backed by strict data privacy policies and significant venture capital.
ZDNet's 2026 RAM Advice: Practical Guidance for PC & Mac
Quick Verdict ZDNet’s deep dive into RAM requirements for 2026 offers a pragmatic, consumer-focused guide for Windows, Mac, and Chromebook users. It clearly establishes 16GB as the new standard for most Windows PCs and
Kratom Civil War Escalates as Health Secretary Targets 7-OH, MAHA
Health Secretary RFK Jr. is pushing to ban 7-OH, an active component of kratom, sparking a "civil war" among advocates. This move follows a previous successful fight against a DEA ban on kratom, highlighting ongoing regulatory challenges and divisions within the advocacy community.
The impossible dream of the universal remote: Logitech Harmony — Key
Tech veterans David Pierce, Nilay Patel, John Higgins, and Nest co-founder Matt Rogers revisit the legacy of the Logitech Harmony universal remote on The Verge’s “Version History” podcast. Despite being the market leader for years, the Harmony ultimately faded, highlighting the persistent challenge of unifying home entertainment control. Its story reveals how even a compelling product can struggle in an evolving tech landscape.






