Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Defender Zero-Day Vulnerability Exposes System Access

Microsoft Defender Zero-Day Vulnerability Exposes System Access

Posted on June 14, 2026 By CWS

An anonymous security expert, known as Chaotic Eclipse, recently published a proof-of-concept (PoC) exploit targeting a zero-day vulnerability in Microsoft Defender, named RoguePlanet. This exploit, which involves a race condition, can yield SYSTEM-level access, potentially allowing malicious actors to execute arbitrary code on affected systems.

Exploit Details and Impact

The exploit has been tested on Windows 11 and Windows 10 systems that have received the June 2026 Patch Tuesday updates, indicating it affects the latest versions of these operating systems. However, it currently does not work on Windows Server instances. Chaotic Eclipse highlighted that the flaw still exists in Windows Server, but the exploit’s design requires adjustments to affect those systems.

Security researcher Will Dormann noted on Mastodon that, while the exploit is not consistently reliable, it functioned successfully on his initial attempt. The exploit raises significant concerns as it can grant attackers unauthorized access to perform harmful actions on compromised systems.

Researcher Disputes and Microsoft’s Stance

Chaotic Eclipse has been involved in ongoing disputes with Microsoft, accusing the company of mishandling vulnerability disclosures and revoking their access to the Microsoft Security Response Center (MSRC). This tension has led to uncoordinated public disclosures of several vulnerabilities, including RoguePlanet, as a form of retaliation.

Microsoft has criticized the public release of such vulnerabilities, arguing that they pose unnecessary risks to users. The company maintains that coordinated vulnerability disclosure is crucial for protecting customers and addressing security issues effectively.

Future Outlook and Reactions

In response to these disclosures, Microsoft stated that it is investigating the reported vulnerabilities and is committed to updating affected products promptly. The company emphasized its support for coordinated vulnerability disclosure to ensure thorough investigation and remediation of security flaws before public disclosure.

The ongoing conflict between Chaotic Eclipse and Microsoft highlights the challenges in vulnerability disclosure processes and the need for clear communication between researchers and companies. As this situation unfolds, the cybersecurity community will be closely monitoring Microsoft’s actions and any further disclosures by Chaotic Eclipse.

The Hacker News Tags:Cybersecurity, Exploit, Microsoft Defender, patch updates, security flaws, SYSTEM access, Vulnerability, Windows 10, Windows 11, zero-day

Post navigation

Previous Post: ServiceNow Security Breach Allows Unauthorized Access
Next Post: Critical Vulnerabilities in Protobuf.js Threaten Node.js Security

Related Posts

Key Capabilities Security Leaders Need to Know Key Capabilities Security Leaders Need to Know The Hacker News
OpenAI Introduces ChatGPT Lockdown Mode for Enhanced Security OpenAI Introduces ChatGPT Lockdown Mode for Enhanced Security The Hacker News
Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack The Hacker News
Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager The Hacker News
SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass The Hacker News
How Smart MSSPs Using AI to Boost Margins with Half the Staff How Smart MSSPs Using AI to Boost Margins with Half the Staff The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerabilities in Protobuf.js Threaten Node.js Security
  • Microsoft Defender Zero-Day Vulnerability Exposes System Access
  • ServiceNow Security Breach Allows Unauthorized Access
  • Anthropic Unveils Claude Fable 5 with Cybersecurity Focus
  • Microsoft Addresses 206 Security Vulnerabilities, Including Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerabilities in Protobuf.js Threaten Node.js Security
  • Microsoft Defender Zero-Day Vulnerability Exposes System Access
  • ServiceNow Security Breach Allows Unauthorized Access
  • Anthropic Unveils Claude Fable 5 with Cybersecurity Focus
  • Microsoft Addresses 206 Security Vulnerabilities, Including Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark