2026-08-12HIGHMicrosoft has now shipped an engine fix (1.1.26080.3), and the same researcher claims a partial bypass of it
RoguePlanet
trend · trend:nightmare-eclipse-rogueplanet-defender-toctou-lpe-2026-06
Nightmare Eclipse's TOCTOU race in the Microsoft Defender scan engine yielding SYSTEM LPE, public PoC, no CVE or patch at disclosure.
Coverage
5
first 2026-06-11 → last 2026-08-12
Latest activity
2026-09-13
Microsoft has now shipped an engine fix (1.1.26080.3), and the same researcher claims a partial bypass of it
Peak priority
high
4 high · 1 notable
Targets
public-sector
sectors: public-sector, energy, healthcare · regions: switzerland, europe
Sources cited
16
14 hosts
Action items (5)
Do-now tasks recorded on the entries about RoguePlanet, newest first. Check the date before acting on an older one.
- Confirm every Windows endpoint reports Microsoft Malware Protection Engine 1.1.26080.3 or later; the engine version updates on its own cadence and is not covered by the OS patch level, so check it separately; 1.26070.7 is the last affected build.2026-08-12CVE-2026-50656 +1
- Hunt for C:\\Windows\\System32\\phoneinfo.dll across the Windows estate now; LevelBlue states the file is not expected to exist natively on supported Windows versions, so an instance on a supported build is either this chain or an unrelated planted DLL, and either warrants investigation.2026-08-12CVE-2026-50656 +1
- On WSUS-gated, air-gapped, offline or OT-adjacent Windows estates where Defender engine updates are deferred or pinned, verify the installed Malware Protection Engine build is ≥ 1.1.26060.3008 (e.g. via Get-MpComputerStatus AMEngineVersion) rather than assuming auto-update reached it.2026-07-09CVE-2026-50656
- Continue tracking the Nightmare Eclipse zero-day series via NCSC-CH's running advisory: RoguePlanet is now fixed, but the same researcher's series has previously dropped further unpatched Defender/Windows PoCs, so treat NCSC-CH's tracker as the authority for the current fix status of each.2026-07-09CVE-2026-50656
- Compensate for the unpatched Defender LPE (CVE-2026-50656) (§ 4). No patch exists, monitor for2026-06-19CVE-2026-50656
MsMpEng.exespawningcmd.exe/powershell.exeas SYSTEM (Sysmon EID 1 parent-image filter, WEL 4688) and constrain which low-privilege accounts can trigger on-demand scans.
Defender insights
What each entry about RoguePlanet tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
exploited by
Story timeline
- 2026-08-12ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025
- 2026-07-09CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series
- 2026-06-19Nightmare/Chaotic Eclipse zero-day wave; the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patch
- 2026-06-12"GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition, PoC public, practical severity contested
- 2026-06-11"RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch
Hunting pivots
Affected products
ATT&CK techniques (12 across 5 tactics)
12 techniques observed across 4 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionScheduled Task/Job: Scheduled Task · Native API · Hijack Execution Flow: DLL
- PersistenceScheduled Task/Job: Scheduled Task · Pre-OS Boot · Pre-OS Boot: System Firmware
- Privilege EscalationScheduled Task/Job: Scheduled Task · Exploitation for Privilege Escalation · Abuse Elevation Control Mechanism
- StealthObfuscated Files or Information: Dynamic API Resolution · Masquerading: Match Legitimate Resource Name or Location · Indicator Removal: File Deletion · System Binary Proxy Execution · Pre-OS Boot · Pre-OS Boot: System Firmware · Hijack Execution Flow: DLL
- Defense ImpairmentDisable or Modify Tools
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1106Native API×1
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1542Pre-OS Boot×1
Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are loaded before the operating system. These programs control flow of execution before the operating system takes control.
Evidence: 2026-06-12/greatxml-unpatched-bitlocker-bypass-via-crafted-xml-on-the-r · ATT&CK page ↗
T1542.001Pre-OS Boot: System Firmware×1
Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.
Evidence: 2026-06-12/greatxml-unpatched-bitlocker-bypass-via-crafted-xml-on-the-r · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1068Exploitation for Privilege Escalation×3
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed · 2026-06-11/rogueplanet-microsoft-defender-zero-day-toctou-race-in-the-s · ATT&CK page ↗
T1548Abuse Elevation Control Mechanism×1
Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
Stealth TA0005
T1027.007Obfuscated Files or Information: Dynamic API Resolution×1
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native API functions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1070.004Indicator Removal: File Deletion×1
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1218System Binary Proxy Execution×1
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1542Pre-OS Boot×1
Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are loaded before the operating system. These programs control flow of execution before the operating system takes control.
Evidence: 2026-06-12/greatxml-unpatched-bitlocker-bypass-via-crafted-xml-on-the-r · ATT&CK page ↗
T1542.001Pre-OS Boot: System Firmware×1
Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.
Evidence: 2026-06-12/greatxml-unpatched-bitlocker-bypass-via-crafted-xml-on-the-r · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
Entries about RoguePlanet (5)
Earlier coverage (2)
"GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition, PoC public, practical severity contested"GreatXML": unpatched BitLocker bypass with public PoC, crafted XML files on the recovery partition yield a SYSTEM shell in WinRE; severity is contested (an initial Defender offline scan, which requires admin, must have run once) (SecurityWeek, 2026-06-11)."RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patchA new Microsoft Defender SYSTEM-LPE zero-day, "RoguePlanet," dropped as a public PoC hours after June Patch Tuesday, a TOCTOU race in the Defender scan engine, no CVE and no patch (BleepingComputer, 2026-06-09). No in-the-wild use reported yet; monitoring is the only mitigation.
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Nightmare Eclipse×5
- Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker×3
- Nightmare Eclipse Windows zero-day series×3
- Microsoft Defender Antivirus×2
- GreatXML×1
- LegacyHive×1
- Microsoft Defender / Malware Protection Engine elevation of privilege, publicly referred to as ShieldBreak, Microsoft's identifier for the proof-of-concept claiming a bypass of the July fix for CVE-2026-50656. Important, CVSS 3.1 base 7.8, publicly disclosed, exploitation not detected, assessed 'Exploitation More Likely'; no update available at publication.×1
- Microsoft Malware Protection Engine×1
Where this entity is cited
Source distribution
- msrc.microsoft.com2 (12%)
- securityweek.com2 (12%)
- attack.mitre.org1 (6%)
- bleepingcomputer.com1 (6%)
- cert.ssi.gouv.fr1 (6%)
- cyberkendra.com1 (6%)
- github.com1 (6%)
- helpnetsecurity.com1 (6%)
- other6 (38%)
All cited sources (16)
- attack.mitre.orgT1542.001https://attack.mitre.org/techniques/T1542/001/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/
- cert.ssi.gouv.frCERT-FR / ANSSIhttps://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1035/
- cyberkendra.comCyber Kendrahttps://www.cyberkendra.com/2026/08/shieldbreak-poc-bypasses-microsofts.html
- github.comNightmare Eclipse, 2026-09-08https://github.com/MSNightmare/ShieldCrash
- helpnetsecurity.comHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/17/rogueplanet-zero-day-cve-2026-50656/
- levelblue.comLevelBlue SpiderLabshttps://www.levelblue.com/blogs/spiderlabs-blog/cloud-sync-root-registrationshieldbreak-hunting-windows-defender-remediation-abuse-and-cloud-files-hijacking
- msrc.microsoft.comMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656
- msrc.microsoft.comMicrosoft Security Response Centerhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
- rapid7.comRapid7https://www.rapid7.com/blog/post/em-patch-tuesday-august-2026/
- security-hub.ncsc.admin.chNCSC-CH GovCERThttps://security-hub.ncsc.admin.ch/#/posts/12622
- securityweek.comSecurityWeekhttps://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/
- securityweek.comSecurityWeekhttps://www.securityweek.com/new-windows-zero-day-exploit-rogueplanet-released/
- socradar.ioSOCRadarhttps://socradar.io/blog/shieldcrash-poc-microsoft-defender-fix-bypass/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html
- theregister.comThe Registerhttps://www.theregister.com/security/2026/06/11/nightmare-eclipse-drops-claimed-bitlocker-bypass-for-microsoft-windows/5254371