2026-07-09NOTABLEMicrosoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June
Nightmare Eclipse Windows zero-day series
campaign · campaign:nightmare-eclipse-microsoft-dcu-threat-greenplasma-miniplasmaaac
Nightmare Eclipse's 2026 public Windows zero-day drop series: YellowKey (BitLocker, later CVE-2026-45585) and GreenPlasma (CTFMON LPE) with public PoCs, MiniPlasma (cldflt.sys CfAbortHydration, claimed CVE-2020-17103 regression on fully patched Windows 11) as the third PoC; after Microsoft's Digital Crimes Unit threatened criminal action the persona threatened a further release for 14 July 2026, with GreenPlasma/MiniPlasma still unpatched.
Coverage
6
first 2026-05-15 → last 2026-07-09
Latest activity
2026-07-09
Microsoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has…
Peak priority
high
3 high · 3 notable
Targets
public-sector
sectors: public-sector, energy, water · regions: switzerland
Sources cited
16
9 hosts
2026-05-156 appearances2026-07-09
Action items (4)
Do-now tasks recorded on the entries about Nightmare Eclipse Windows zero-day series, newest first. Check the date before acting on an older one.
- On WSUS-gated, air-gapped, offline or OT-adjacent Windows estates where Defender engine updates are deferred or pinned, verify the installed Malware Protection Engine build is ≥ 1.1.26060.3008 (e.g. via Get-MpComputerStatus AMEngineVersion) rather than assuming auto-update reached it.2026-07-09CVE-2026-50656
- Continue tracking the Nightmare Eclipse zero-day series via NCSC-CH's running advisory: RoguePlanet is now fixed, but the same researcher's series has previously dropped further unpatched Defender/Windows PoCs, so treat NCSC-CH's tracker as the authority for the current fix status of each.2026-07-09CVE-2026-50656
- Enforce BitLocker pre-boot PIN on all managed Windows laptops and enforce BIOS/UEFI boot password, YellowKey (no CVE) bypasses TPM-only BitLocker via WinRE with a public PoC. Group Policy path:2026-05-15CVE-2026-45585
Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives > Require additional authentication at startup→ Enable + require PIN. Disable WinRE access where operationally viable (reagentc /disable). - Add BitLocker PIN / password protector to TPM-only-protected endpoints (CVE-2026-45585 / YellowKey). Microsoft's WinRE2026-05-15CVE-2026-45585
BootExecuteregistry mitigation is per-device and fragile under Windows feature updates that re-stage WinRE; the PIN/password protector closes the bypass regardless of WinRE state. Public PoC, no patch (MSRC CVE-2026-45585).
Defender insights
What each entry about Nightmare Eclipse Windows zero-day series tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
attributed to
exploits
Story timeline
- 2026-07-09CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series
- 2026-06-12"GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition, PoC public, practical severity contested
- 2026-06-11"RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch
- 2026-05-30Nightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop
- 2026-05-19Chaotic Eclipse Windows zero-days; MiniPlasma is third PoC in series; cldflt.sys CfAbortHydration path, claimed re-exploitable CVE-2020-17103 regression
- 2026-05-15Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassed
Hunting pivots
Affected products
ATT&CK techniques (5 across 3 tactics)
5 techniques observed across 5 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- PersistencePre-OS Boot · Pre-OS Boot: System Firmware
- Privilege EscalationExploitation for Privilege Escalation · Access Token Manipulation
- StealthDirect Volume Access · Access Token Manipulation · Pre-OS Boot · Pre-OS Boot: System Firmware
Persistence TA0003
T1542Pre-OS Boot×1
Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are loaded before the operating system. These programs control flow of execution before the operating system takes control.
Evidence: 2026-06-12/greatxml-unpatched-bitlocker-bypass-via-crafted-xml-on-the-r · ATT&CK page ↗
T1542.001Pre-OS Boot: System Firmware×2
Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.
Evidence: 2026-06-12/greatxml-unpatched-bitlocker-bypass-via-crafted-xml-on-the-r · 2026-05-15/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-zero-days · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×4
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed · 2026-06-11/rogueplanet-microsoft-defender-zero-day-toctou-race-in-the-s · 2026-05-19/chaotic-eclipse-windows-zero-days-miniplasma-is-third-poc-in · 2026-05-15/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-zero-days · ATT&CK page ↗
T1134Access Token Manipulation×1
Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the process. When this occurs, the process also takes on the security context associated with the new token.
Evidence: 2026-05-15/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-zero-days · ATT&CK page ↗
Stealth TA0005
T1006Direct Volume Access×1
Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique may bypass Windows file access controls as well as file system monitoring tools.
Evidence: 2026-05-15/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-zero-days · ATT&CK page ↗
T1134Access Token Manipulation×1
Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the process. When this occurs, the process also takes on the security context associated with the new token.
Evidence: 2026-05-15/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-zero-days · ATT&CK page ↗
T1542Pre-OS Boot×1
Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are loaded before the operating system. These programs control flow of execution before the operating system takes control.
Evidence: 2026-06-12/greatxml-unpatched-bitlocker-bypass-via-crafted-xml-on-the-r · ATT&CK page ↗
T1542.001Pre-OS Boot: System Firmware×2
Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.
Evidence: 2026-06-12/greatxml-unpatched-bitlocker-bypass-via-crafted-xml-on-the-r · 2026-05-15/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-zero-days · ATT&CK page ↗
Entries about Nightmare Eclipse Windows zero-day series (6)
Earlier coverage (3)
Nightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 dropUPDATE (originally covered 2026-W21): Microsoft's Digital Crimes Unit issued a formal public statement on 28–29 May 2026 calling uncoordinated zero-day releases "never justifiable" and warning its DCU would "continue bringing cases against these actors and those that enable their criminal activity" (The Record …Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassedWindows BitLocker "YellowKey" zero-day (no CVE) bypasses TPM-only disk encryption via WinRE NTFS transaction replay; working PoC is public; no patch available; add BitLocker pre-boot PIN to close the current PoC (BleepingComputer, 2026-05-13).Chaotic Eclipse Windows zero-days; MiniPlasma is third PoC in series; cldflt.sys CfAbortHydration path, claimed re-exploitable CVE-2020-17103 regressionUPDATE (originally covered 2026-05-15): Researcher "Chaotic Eclipse" / "Nightmare Eclipse" released a third unpatched Windows LPE PoC on 2026-05-17 (MiniPlasma) extending the YellowKey and GreenPlasma series covered in the 2026-05-15 daily (BleepingComputer, 2026-05-17; The Hacker News, 2026-05-18).
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Nightmare Eclipse×6
- RoguePlanet×3
- Windows YellowKey BitLocker bypass via WinRE×2
- GreatXML×1
- Microsoft Defender Antivirus×1
- Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker×1
- Microsoft Security Essentials×1
- Microsoft System Center Endpoint Protection×1
Where this entity is cited
Source distribution
- bleepingcomputer.com3 (19%)
- msrc.microsoft.com3 (19%)
- security-hub.ncsc.admin.ch2 (12%)
- securityweek.com2 (12%)
- theregister.com2 (12%)
- attack.mitre.org1 (6%)
- heise.de1 (6%)
- thehackernews.com1 (6%)
- other1 (6%)
All cited sources (16)
- attack.mitre.orgT1542.001https://attack.mitre.org/techniques/T1542/001/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/
- bleepingcomputer.comBleepingComputer, 2026-05-13https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/
- heise.deheise Securityhttps://www.heise.de/en/news/Too-many-zero-days-Microsoft-threatens-legal-action-11310736.html
- msrc.microsoft.comMSRC CVE-2026-45585, 2026-05-19https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585
- msrc.microsoft.comMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
- msrc.microsoft.comMicrosoft Security Response Centerhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656
- security-hub.ncsc.admin.chNCSC-CH Security Hub #12574, 2026-05-14https://security-hub.ncsc.admin.ch/#/posts/12574
- security-hub.ncsc.admin.chNCSC-CH GovCERThttps://security-hub.ncsc.admin.ch/#/posts/12622
- securityweek.comSecurityWeekhttps://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/
- securityweek.comSecurityWeekhttps://www.securityweek.com/new-windows-zero-day-exploit-rogueplanet-released/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/05/miniplasma-windows-0-day-enables-system.html
- therecord.mediaThe Recordhttps://therecord.media/microsoft-calls-zero-day-releases-never-justifiable-as-researcher-threatens-more
- theregister.comThe Register, 2026-05-13https://www.theregister.com/security/2026/05/13/disgruntled-researcher-releases-two-more-microsoft-zero-days/5239758
- theregister.comThe Registerhttps://www.theregister.com/security/2026/06/11/nightmare-eclipse-drops-claimed-bitlocker-bypass-for-microsoft-windows/5254371