Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

Microsoft June Patch Tuesday: RoguePlanet Zero-Day Bypasses Defender Protection

Following June's Patch Tuesday, a researcher discloses the Defender vulnerability RoguePlanet. Microsoft's emergency update can already be bypassed.

What happened?

On June's Patch Tuesday, Microsoft closed numerous security vulnerabilities in products such as Azure, Microsoft 365, Exchange Online, Office, and Windows, classifying many of them as "critical." In several cases, attackers could execute malicious code remotely without authentication and fully compromise affected systems. No sooner had Patch Tuesday concluded than a security researcher going by the pseudonym Nightmare Eclipse published details of a further, previously unknown vulnerability called RoguePlanet on their blog – a so-called zero-day that affects even fully patched Windows 10 and Windows 11 systems.

The details

Among the vulnerabilities closed on Patch Tuesday were also two BitLocker zero-days that the same researcher had previously disclosed: YellowKey (CVE-2026-45585, "medium" severity) and GreenPlasma (CVE-2026-50507, also "medium"). If successfully exploited, these vulnerabilities allow attackers to bypass BitLocker drive encryption.

The newly disclosed RoguePlanet vulnerability once again targets the Windows Defender security software. If an attack succeeds, the attackers gain system privileges on the affected machine – the highest privilege level in Windows. Microsoft responded comparatively quickly: as early as the morning of June 10, Defender definition update 1.453.20.0 was released, adding detection for RoguePlanet and aiming to quarantine the associated exploit.

However, this detection proves to be far from robust: according to the editorial team's own tests, the protection can be bypassed with a trivial modification to the source code of the proof-of-concept exploit, once again allowing a shell with system privileges to be executed. So far, there is no evidence that attackers are actively exploiting RoguePlanet in the wild. The anonymous researcher also announced having further zero-days in hand, originally planned for disclosure on July 14. Due to the extra work surrounding RoguePlanet, this date is being postponed – no new date has been announced yet.

Assessment

This case illustrates how dynamically the threat landscape surrounding core Windows security components can evolve. Even the already actively exploited vulnerability RedSun (CVE-2026-41091, "high") in Defender's Malware Protection Engine had to be corrected again after an earlier fix from late May apparently proved insufficient. Microsoft is now officially listing this correction under June's Patch Tuesday.

In addition, there are three already publicly known vulnerabilities in Windows – in HTTP.sys, BitLocker, and the Collaborative Translation Framework (CVE-2026-49160 "high," CVE-2026-50507 "medium," CVE-2026-45586 "high") – where attacks could be imminent since the details are already public. Three further vulnerabilities rated "critical" affect the Windows kernel (CVE-2026-45657), HTTP.sys again (CVE-2026-47291), and the Windows DHCP Client Service (CVE-2026-44815). In all these cases, attackers could execute malicious code and fully take over systems.

For operators of security-relevant infrastructure – ranging from corporate networks to systems controlling physical security technology such as access control or alarm systems – this accumulation of critical Windows vulnerabilities is of particular significance. Many security solutions, such as video surveillance management software or networked access control systems, run on a Windows basis and are therefore potentially just as affected as standard office IT.

Practical tips

  • Install Patch Tuesday updates promptly: The critical vulnerabilities closed in June's Patch Tuesday should be prioritized and installed without unnecessary delay.
  • Check Defender definition updates: Since automatic detection of RoguePlanet is considered inadequate, additional protective measures such as endpoint detection and response solutions and restrictive privilege management should be considered.
  • Review BitLocker configuration: Anyone encrypting sensitive data – such as logs from alarm systems or video surveillance systems – with BitLocker should patch the affected systems promptly to prevent the encryption from being bypassed.
  • Secure systems with system privileges in particular: Since RoguePlanet grants attackers system privileges, additional segmentation and monitoring are advisable on critical servers, such as those managing access control systems or Wardhub connections.
  • Keep an eye on publicly known but not yet exploited vulnerabilities: Systems using HTTP.sys, BitLocker, or the Collaborative Translation Framework should be updated as a priority, since attacks could be imminent here.

Outlook

The anonymous researcher's announcement of further zero-days suggests that the series of Defender and BitLocker vulnerabilities is not yet over. No concrete release date for the remaining vulnerabilities has been set at this time, which poses a challenge for security teams having to respond quickly to new findings. Given the rather rudimentary detection of RoguePlanet by Microsoft's definition update so far, further improvements are likely to follow. Operators of security-critical systems – from traditional IT environments to networked security technology such as deposit safes with digital logging or offertory box systems with electronic monitoring – should closely monitor further developments regarding these vulnerabilities and tighten their patch processes accordingly.