Microsoft Updates ‘RoguePlanet’ Defender for Zero-Day Issue, Fresh Vulnerabilities Identified by Researcher
We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!
Microsoft Reinforces Windows Defender Against ‘RoguePlanet’ Zero-Day Vulnerability
Quick Overview
- Microsoft resolves ‘RoguePlanet’, a significant zero-day flaw in Windows Defender.
- Following the update, additional vulnerabilities have been identified by the researcher.
- These include an information leak and a denial-of-service issue.
- The newly found vulnerabilities have not yet been verified by Microsoft or assigned a CVE number.
- The researcher, Nightmare Eclipse, has a track record of revealing various security vulnerabilities.
Tackling RoguePlanet Flaw
Microsoft has addressed a crucial zero-day vulnerability termed ‘RoguePlanet’ in its Windows Defender scanning engine. This flaw enabled local attackers to gain elevated privileges and potentially execute a SYSTEM-level shell. Rated 7.8 on the CVSS scale, this vulnerability was mitigated with an update to the Windows Defender Malware Protection Engine, currently at version 1.1.26060.3008.
New Worries: Additional Vulnerabilities
After the fix, the researcher known as Nightmare Eclipse brought attention to two more security concerns in Windows Defender. One issue involves an eight-byte information leak, reportedly originating from Microsoft’s defense-in-depth strategies. However, the leak appears not to impact standard user processes outside Windows kernel drivers.
The second problem includes a denial-of-service vulnerability. This flaw takes advantage of the Defender’s caching mechanism for Zone.Identifier, potentially causing disk exhaustion. The researcher illustrated this by establishing a rogue SMB server to manipulate Defender’s file handling, leading to crashes and excessive disk space usage.
Researcher Background and Prior Discoveries
Nightmare Eclipse, also referred to as Chaotic Eclipse, has a notable history of identifying vulnerabilities within Microsoft products. Past discoveries encompass the BlueHammer, RedSun, and UnDefend vulnerabilities, all of which were exploited in the wild prior to patch releases. These findings are included in CISA’s Known Exploited Vulnerabilities database.
Microsoft initially condemned the researcher’s disclosure tactics but later rescinded legal threats after facing criticism from the security community.
Conclusion
While Microsoft has effectively patched the RoguePlanet vulnerability, ongoing discoveries by researchers like Nightmare Eclipse underscore the dynamic nature of cybersecurity risks. Users are urged to keep their systems updated and remain alert to possible exploits.
Reader questions
Frequently asked questions
Fast answers to the questions readers ask most about Microsoft Updates 'RoguePlanet' Defender for Zero-Day Issue, Fresh Vulnerabilities Identified by Researcher.
What is the RoguePlanet vulnerability?
RoguePlanet is a zero-day exploit present in Windows Defender that enables privilege escalation, which may lead to SYSTEM-level shell execution.
How has Microsoft tackled the RoguePlanet issue?
Microsoft has mitigated the vulnerability by updating the Windows Defender Malware Protection Engine to version 1.1.26060.3008.
Are there any additional vulnerabilities associated with the RoguePlanet patch?
Indeed, the researcher has identified an information leak and a denial-of-service vulnerability subsequent to the patch.
Has Microsoft verified the new vulnerabilities?
At this moment, Microsoft has not confirmed these new discoveries or assigned CVE identifiers to them.
Who is the researcher responsible for these findings?
The vulnerabilities were uncovered by a researcher known as Nightmare Eclipse or Chaotic Eclipse.
How has the security community reacted to Microsoft's actions?
The community expressed backlash after Microsoft initially threatened legal measures against the researcher, prompting a withdrawal of those threats.
What actions should users take to ensure their safety?
Users should routinely update their systems and antivirus software to the latest versions to protect against known vulnerabilities.
