
Validation report for the RoguePlanet Microsoft Defender PoC in a controlled Windows 11 lab environment, including build notes, Defender detection results, risk assessment, and mitigation recommendations.
This report concerns the validation of the publicly described RoguePlanet PoC related to Microsoft Defender. The described technique was presented in the media on 10 June 2026 as a Local Privilege Escalation (LPE), in which a local user can obtain NT AUTHORITY\SYSTEM privileges. Public descriptions indicated that the mechanism uses functions used by Microsoft Defender when handling or scanning a file.
The purpose of the test was to determine whether the exploit could be prepared and executed in a controlled laboratory environment, and to observe how Microsoft Defender protection mechanisms behave on an up-to-date Windows 11 system. The report covers the test environment, update status, Microsoft Defender configuration, preparation of the compilation environment, compilation result, Defender response, and risk-reduction recommendations.
The test was research-oriented and was performed locally on a dedicated test workstation. The results should be interpreted as an assessment of the behavior of a specific artifact and a specific environment configuration, not as full confirmation of resistance to all possible variants of this technique.
Sources referenced in the analyzed material:
Article:
https://thehackernews.com/2026/06/microsoft-defender-rogueplanet-zero-day.html
Public PoC repository:
MSYS2 installer source:
https://github.com/msys2/msys2-installer/releases/tag/nightly-x86_64
Visual Studio source:
The PoC was performed on a client workstation operating outside an Active Directory domain, in the WORKGROUP workgroup. The operating system installed on the workstation was Microsoft Windows 11 Home, version 25H2, 64-bit architecture.
| Parameter | Value |
|---|---|
| System name | Microsoft Windows 11 Home |
| Edition | Home |
| System version | 25H2 |
| OS version | 10.0.26200 |
| Build number | 26200 |
| Architecture | x64 / 64-bit |
| Installation type | Client / Workstation |
| Host name | LAPTOP-80LPIEH2 |
| Device manufacturer | Lenovo |
| Device model | Lenovo Legion Slim 5 16IRH8 |
| Processor | 12th Gen Intel(R) Core(TM) i5-12450H |
| RAM | 32 GB |
On the day the PoC was performed, the system had the June 2026 security updates installed, as well as earlier updates from May and April 2026. This means that the test was carried out on an up-to-date Windows 11 25H2 system, build 26200, after installation of the latest available security patches as of the test date.
| HotFixID | Update type | Installation date |
|---|---|---|
| KB5094135 | Security Update | 10.06.2026 |
| KB5094126 | Security Update | 10.06.2026 |
| KB5087051 | Update | 14.05.2026 |
| KB5092762 | Security Update | 13.05.2026 |
| KB5054156 | Update | 28.04.2026 |
Microsoft Defender Antivirus was active on the workstation used for the test and was running in normal mode. The protection service was running and enabled, and antivirus protection, antispyware protection, behavior monitoring, and real-time protection were active.
| Parameter | Value |
|---|---|
| AMProductVersion | 4.18.26050.15 |
| AMServiceVersion | 4.18.26050.15 |
| AMEngineVersion | 1.1.26050.11 |
| AMRunningMode | Normal |
| AMServiceEnabled | True |
| AntivirusEnabled | True |
| AntispywareEnabled | True |
| RealTimeProtectionEnabled | True |
| BehaviorMonitorEnabled | True |
| OnAccessProtectionEnabled | True |
| IoavProtectionEnabled | True |
| NISEnabled | True |
| NISEngineVersion | 1.1.26050.11 |
| IsTamperProtected | True |
| DefenderSignaturesOutOfDate | False |
| RebootRequired | False |
| IsVirtualMachine | False |
On the day of the test, Microsoft Defender signatures were up to date. Antivirus, antispyware, and NIS signatures had been updated on 10.06.2026 at 13:27:32.
| Signature type | Version | Last update date |
|---|---|---|
| AntivirusSignatureVersion | 1.453.27.0 | 10.06.2026 13:27:32 |
| AntispywareSignatureVersion | 1.453.27.0 | 10.06.2026 13:27:32 |
| NISSignatureVersion | 1.453.27.0 | 10.06.2026 13:27:32 |
The last quick scan was performed on 08.06.2026 between 15:00:36 and 15:01:58, using signatures version 1.451.323.0. A full scan had not been performed previously or its history was not available, as indicated by the FullScanAge value of 4294967295 and the absence of full scan start and end times.
The first attempt to compile the code from the GitHub repository ended with an error caused by the missing winternl.h header. The message indicated that the system did not have the complete set of Windows SDK headers required by the analyzed code.

Figure 1. Missing winternl.h header error during the first compilation attempt.
The code also referenced other headers related to Windows API and NT API, including windows.h, Psapi.h, ntstatus.h, virtdisk.h, shlwapi.h, taskschd.h, and bcrypt.h. For this reason, it was necessary to prepare a more complete compilation environment and install the appropriate SDK components.

Figure 2. Fragment of the list of headers required by the analyzed code.
Initially, MSYS2/MinGW-w64 was used to prepare the compilation environment. This environment provides GNU tools for Windows, including the gcc and g++ compilers. Packages in MSYS2 are managed using pacman, which serves a similar role to apt on Linux systems or winget on Windows.

Figure 3. Completion of the MSYS2 installation.
Using pacman, the MinGW-w64 GCC/G++ toolchain was installed, i.e. a set of tools that enables compilation of C/C++ code for Windows. The package includes, among other components, the gcc compiler, the g++ C++ compiler, the linker, and the headers and libraries required to build applications running in the Windows environment. The purpose of this attempt was to check whether the code could be compiled using the open toolchain available in MSYS2, without using Visual Studio.
