Researcher publishes RoguePlanet PoC for an unpatched Microsoft Defender zero-day on Windows 10 and 11
The proof-of-concept abuses a race condition to spawn a SYSTEM shell on fully patched machines. No fix exists, though the exploit is unreliable by nature.
A security researcher has published a working proof-of-concept exploit for an unpatched privilege-escalation flaw in Microsoft Defender that can grant SYSTEM-level access on fully updated Windows 10 and 11 machines.
The researcher, who uses the alias Chaotic Eclipse, released the exploit — named RoguePlanet, tracked as CVE-2026-47281 — on June 9, 2026, hours after Microsoft's June Patch Tuesday, in a public GitHub repository. It abuses a time-of-check to time-of-use (TOCTOU) race condition in Windows Defender to spawn a SYSTEM-level command shell. Tested on Windows 10 and 11 with the June 2026 updates installed, the exploit is unreliable by nature because of the race condition, though the researcher reported a 100 percent success rate on some machines.
The key caveat is that this is a researcher's proof of concept, not evidence of an active attack campaign. There is no confirmation of in-the-wild exploitation of CVE-2026-47281, and the exploit does not work on Windows Server in its current form because standard users there cannot mount ISO images, though the researcher claims Server versions are vulnerable as well. Other researchers have reported independently reproducing the technique, suggesting it is real even if its reliability varies.
No patch is available. Microsoft has said it is aware of the reported vulnerability and is investigating, a statement it has not posted to its own advisory channel.
The disclosure raises the stakes because RoguePlanet is the fourth Defender zero-day from this researcher since April 2026, after BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498) and RedSun (CVE-2026-41091), earlier flaws that were later exploited in the wild. That track record is the strongest reason to treat the new flaw as a near-term risk rather than a curiosity, even before any patch arrives.
An entrepreneur with over a decade of experience in AI, Cloud, and HPC. He is currently a DevOps Architect and the founder of Data Phoenix, an influential media voice for the AI industry, with a strong focus on community building and open source.
More news

Local process can redirect Meta Muse dictation traffic on macOS

Security firm Mindgard publicly discloses unpatched Cursor code-execution flaw after seven-month stall

Cisco discloses actively exploited SD-WAN Manager zero-day as CISA orders federal patch by June 29
Dmytro Spodarets·Jun 16, 2026
Microsoft's June Patch Tuesday fixes a record 206 vulnerabilities
Dmytro Spodarets·Jun 11, 2026