Microsoft's bug-hunting nemesis extends vendetta with more zero-day attacks — Nightmare Eclipse publishes RoguePlanet and GreatXML local privilege escalation exploits
Nightmare-Eclipse published two new Windows zero-day exploits — RoguePlanet targets Windows Defender for SYSTEM-level access, while GreatXML bypasses BitLocker encryption on fully patched systems.

Nightmare-Eclipse Strikes Again: Two New Windows Zero-Day Exploits Published
The ongoing cat-and-mouse game between Microsoft and the elusive security researcher known as Nightmare-Eclipse (also operating under the alias Chaotic-Eclipse) has escalated once again. This week, the researcher published two new zero-day exploits targeting core Windows security features: RoguePlanet and GreatXML, both capable of local privilege escalation on fully patched Windows systems.
RoguePlanet: SYSTEM-Level Access Through Windows Defender
RoguePlanet is the more dangerous of the two exploits. It leverages a previously unknown vulnerability in Windows Defender to grant attackers SYSTEM-level privileges—a permission tier even higher than the standard Administrator account. With SYSTEM access, an attacker can execute arbitrary commands, siphon sensitive data, install persistent malware, and effectively take full control of the machine.
The exploit operates through a race condition between ISO mounting and Volume Shadow Copy services. This timing-dependent mechanism means that while the exploit achieved a 100% success rate on certain Windows installations, it "struggled to work on others," according to Eclipse's own notes. Critically, RoguePlanet functions on fully patched Windows systems—including those running the June 2026 Patch Tuesday updates—underscoring the sophistication of the attack vector.
Eclipse also indicated that Windows Server is likely vulnerable to the same exploit, though the proof-of-concept code would require modifications to account for the fact that Server editions cannot mount ISOs by default.
GreatXML: BitLocker Bypass Raises New Questions
The second exploit, GreatXML, is a BitLocker bypass—though one with stricter conditions than the infamous YellowKey exploit that preceded it. To execute the bypass, an attacker must write a specially crafted unattend.xml file and a Recovery directory to the Windows recovery partition. If a Windows Defender Offline Scan has been run previously, rebooting into the Windows Recovery Environment (WinRE) will unlock the BitLocker-protected drive without requiring the encryption key.
While the attack's prerequisites are admittedly high—requiring write access to the recovery partition—the very existence of such a bypass raises uncomfortable questions about backdoor-like behaviors embedded in BitLocker and WinRE. Eclipse has suggested that it may be possible to trigger a Defender Offline Scan remotely without requiring a user to log in, though this remains unconfirmed.
Escalating Conflict with Microsoft
The release of these exploits marks another chapter in an increasingly bitter conflict between the researcher and Microsoft. The software giant previously banned Eclipse's GitHub account, prompting the researcher to move proof-of-concept code to the Church of Malware—a relatively unrestricted community repository. Ironically, a secondary GitHub account belonging to Eclipse remains active.
Microsoft also threatened legal action against Eclipse earlier this year but has since backed down from that position. For their part, Eclipse had previously threatened to mass-disclose Windows zero-day vulnerabilities on July 14, warning of a "Windowspocalypse." However, the researcher has since relented, citing the unexpected complexity of developing the RoguePlanet exploit as a factor in delaying the mass-disclosure timeline.
Implications for Windows Security
The RoguePlanet and GreatXML exploits demonstrate that even Microsoft's most fundamental security layers—Windows Defender antivirus, BitLocker encryption, and the Windows Recovery Environment—can be subverted by a determined researcher. The fact that these exploits work on fully updated systems is particularly concerning for enterprise environments where patch compliance alone is relied upon for defense.
Organizations should monitor these developments closely. While the practical risk to most users remains low given the need for local access to execute these exploits, the techniques demonstrated by Nightmare-Eclipse often foreshadow broader attack patterns that nation-state actors and sophisticated cybercriminal groups may adopt.
As the July 14 mass-disclosure deadline approaches—even with Eclipse indicating a potential delay—Microsoft faces mounting pressure to address the class of vulnerabilities that RoguePlanet and GreatXML represent, rather than playing a game of whack-a-mole with individual patches.

