Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Defender Zero-Day Vulnerability Exposes System Access

Microsoft Defender Zero-Day Vulnerability Exposes System Access

Posted on June 14, 2026 By CWS

An anonymous security expert, known as Chaotic Eclipse, recently published a proof-of-concept (PoC) exploit targeting a zero-day vulnerability in Microsoft Defender, named RoguePlanet. This exploit, which involves a race condition, can yield SYSTEM-level access, potentially allowing malicious actors to execute arbitrary code on affected systems.

Exploit Details and Impact

The exploit has been tested on Windows 11 and Windows 10 systems that have received the June 2026 Patch Tuesday updates, indicating it affects the latest versions of these operating systems. However, it currently does not work on Windows Server instances. Chaotic Eclipse highlighted that the flaw still exists in Windows Server, but the exploit’s design requires adjustments to affect those systems.

Security researcher Will Dormann noted on Mastodon that, while the exploit is not consistently reliable, it functioned successfully on his initial attempt. The exploit raises significant concerns as it can grant attackers unauthorized access to perform harmful actions on compromised systems.

Researcher Disputes and Microsoft’s Stance

Chaotic Eclipse has been involved in ongoing disputes with Microsoft, accusing the company of mishandling vulnerability disclosures and revoking their access to the Microsoft Security Response Center (MSRC). This tension has led to uncoordinated public disclosures of several vulnerabilities, including RoguePlanet, as a form of retaliation.

Microsoft has criticized the public release of such vulnerabilities, arguing that they pose unnecessary risks to users. The company maintains that coordinated vulnerability disclosure is crucial for protecting customers and addressing security issues effectively.

Future Outlook and Reactions

In response to these disclosures, Microsoft stated that it is investigating the reported vulnerabilities and is committed to updating affected products promptly. The company emphasized its support for coordinated vulnerability disclosure to ensure thorough investigation and remediation of security flaws before public disclosure.

The ongoing conflict between Chaotic Eclipse and Microsoft highlights the challenges in vulnerability disclosure processes and the need for clear communication between researchers and companies. As this situation unfolds, the cybersecurity community will be closely monitoring Microsoft’s actions and any further disclosures by Chaotic Eclipse.

The Hacker News Tags:Cybersecurity, Exploit, Microsoft Defender, patch updates, security flaws, SYSTEM access, Vulnerability, Windows 10, Windows 11, zero-day

Post navigation

Previous Post: ServiceNow Security Breach Allows Unauthorized Access
Next Post: Critical Vulnerabilities in Protobuf.js Threaten Node.js Security

Related Posts

CISO’s Expert Guide To AI Supply Chain Attacks CISO’s Expert Guide To AI Supply Chain Attacks The Hacker News
Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers The Hacker News
Redis Security Flaws Lead to Critical Patches Redis Security Flaws Lead to Critical Patches The Hacker News
Ransomware Negotiator Sentenced for BlackCat Involvement Ransomware Negotiator Sentenced for BlackCat Involvement The Hacker News
Google Halts Major Cyber Espionage Campaign Targeting 53 Entities Google Halts Major Cyber Espionage Campaign Targeting 53 Entities The Hacker News
Cybersecurity Threats: DeFi Hack & AI Vulnerabilities Cybersecurity Threats: DeFi Hack & AI Vulnerabilities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical NGINX Vulnerability Enables Remote Code Execution
  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical NGINX Vulnerability Enables Remote Code Execution
  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark