RoguePlanet zero-day exploit in Microsoft Defender

The researcher using the name Nightmare Eclipse A new Microsoft Defender zero-day exploit called “RoguePlanet” has been released. The exploit reportedly works on fully updated Windows 10 and 11 systems and can create a command prompt with SYSTEM privileges in Defender.

The release came just hours after Microsoft fixed two disclosed flaws during its latest monthly Patch Tuesday release — the largest Patch Tuesday release it has ever made.

See more articles from iGuRu.gr when you search for news on Google.

BleepingComputer reports :

The researcher shared a proof-of-concept exploit Tuesday afternoon on a self-hosted Git repository, after the GitHub and GitLab repositories hosting his exploits were removed by Microsoft. “The exploit is a race condition, so it’s hit or miss. I managed to get a 100% success rate on some machines, while it struggled to work on others,” Nightmare Eclipse says in the repository.

Security firm ThreatLocker told BleepingComputer that it successfully reproduced the flaw in its testing and confirmed that the exploit works on fully updated Windows 11 systems with KB5094126 installed.

“Our initial analysis confirms that the RoguePlanet exploit is viable and works as described. Organizations that use whitelisting can prevent the exploit from executing, providing an effective layer of protection against this attack,” Danny Jenkins, CEO of ThreatLocker, told BleepingComputer.

According to Nightmare Eclipse, RoguePlanet was originally developed as a remote code execution vulnerability that exploited Microsoft Defender's handling of files hosted on remote SMB shares.

“In the initial deployment, this vulnerability was confirmed to be a remote code execution vulnerability,” the researcher explained in a blog post.

“It takes an attacker to force a victim to open a .vhd(x) on a remote SMB server, and the exploit will cause the defender to overwrite its own files and obviously the end result will be an RCE.”

The researcher says that another attack scenario could lead to remote code execution simply by forcing a victim to open an SMB share if symlink evaluation settings are enabled.

However, the researcher claims that Microsoft silently patched Defender in mid-May, updating the “mpengine!SysIO*” API, which blocked junction attacks.

"Rewriting RoguePlanet to make it work again tired me out and I couldn't finish the other scripts, and it remains unclear at this time whether RoguePlanet is limited to being an LPE or if there is some way to turn it into an RCE."


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).