RoguePlanet: Windows 0-day privilege escalation

parliament321 pts0 comments

GitHub - MSNightmare/RoguePlanet: RoguePlanet Windows Defender Vulnerability · GitHub

/" data-turbo-transient="true" />

Skip to content

Search or jump to...

Search code, repositories, users, issues, pull requests...

-->

Search

Clear

Search syntax tips

Provide feedback

--><br>We read every piece of feedback, and take your input very seriously.

Include my email address so I can be contacted

Cancel

Submit feedback

Saved searches

Use saved searches to filter your results more quickly

-->

Name

Query

To see all available qualifiers, see our documentation.

Cancel

Create saved search

Sign in

/;ref_cta:Sign up;ref_loc:header logged out"}"<br>Sign up

Appearance settings

Resetting focus

You signed in with another tab or window. Reload to refresh your session.<br>You signed out in another tab or window. Reload to refresh your session.<br>You switched accounts on another tab or window. Reload to refresh your session.

Dismiss alert

{{ message }}

MSNightmare

RoguePlanet

Public

Notifications<br>You must be signed in to change notification settings

Fork<br>31

Star<br>127

main

BranchesTags

Go to file

CodeOpen more actions menu

Folders and files<br>NameNameLast commit message<br>Last commit date<br>Latest commit

History<br>4 Commits<br>4 Commits

LICENSE

LICENSE

README.md

README.md

RoguePlanet.cpp

RoguePlanet.cpp

RoguePlanet.exe

RoguePlanet.exe

RoguePlanet.png

RoguePlanet.png

View all files

Repository files navigation

RoguePlanet

RoguePlanet Windows Defender Vulnerability

Welcome back everyone !!!

The exploit is a race condition, so it's a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others.

The exploit has been tested in Windows 11 (Official channel + Canary) and Windows 10 with june 2026 patch installed. The PoC however does not work in Windows Server since standard users cannot mount an ISO image, I'm confident that all Windows Server versions are vulnerable as well but by the time I figured out it that the PoC doesn't work in Windows Server installations, it was a too late to redesign the exploit to overcome this issue. But I want to make one thing very clear. All Windows Server installations are vulnerable as well, you just need to redesign the exploit.

The race condition part is a bit interesting, I believe (but not sure) that a redesign of the PoC can make it achieve a 100% success rate regardless of the conditions but honestly I'm done with this bug.

If the exploit succeeds, a SYSTEM shell will be spawned

About

RoguePlanet Windows Defender Vulnerability

Resources

Readme

License

MIT license

Uh oh!

There was an error while loading. Please reload this page.

Activity

Stars

127<br>stars

Watchers

watching

Forks

31<br>forks

Report repository

Releases

No releases published

Packages

Uh oh!

There was an error while loading. Please reload this page.

Contributors

Uh oh!

There was an error while loading. Please reload this page.

Languages

C++<br>100.0%

You can’t perform that action at this time.

rogueplanet windows reload search exploit license

Related Articles