Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityprivilege-escalation-methodinternet-facing-service-vulnerability

Microsoft patches 200 flaws as BitLocker zero-day and Defender RoguePlanet emerge

Updated 1d agoFirst seen Jun 10, 202627 sources

Microsoft released its largest Patch Tuesday update on record, fixing 200 vulnerabilities across Windows, Office, Azure, Exchange Server, .NET Framework, Hyper-V, Remote Desktop Services, and HTTP.sys, including 33 critical flaws and three publicly disclosed zero-days. The disclosed issues include CVE-2026-50507, a BitLocker security feature bypass that can let an attacker with physical access recover data from affected Windows devices; CVE-2026-49160, an HTTP/2 denial-of-service flaw affecting IIS and services built on HTTP.sys; and CVE-2026-45586, a Windows CTFMON privilege-escalation bug that can give a logged-in attacker SYSTEM privileges. Researchers also highlighted CVE-2026-45657, a wormable Windows kernel use-after-free vulnerability rated CVSS 9.8 that could enable remote, unauthenticated code execution as SYSTEM.

At the same time, security researcher Nightmare Eclipse publicly released RoguePlanet, a separate unpatched Microsoft Defender zero-day exploit that reportedly works on fully updated Windows 10 and Windows 11 systems by abusing a race condition to spawn a SYSTEM-level shell, though reports say it is unreliable and does not currently work on Windows Server in its present form. The BitLocker flaw was disclosed before patches were available and is considered more likely to be exploited, with particular concern for TPM-only deployments because possession of a device may be enough to access protected data. Defenders were urged to rapidly deploy the June cumulative updates, prioritize internet-facing Windows and IIS systems, verify patch compliance, review BitLocker configurations, consider TPM+PIN, and monitor endpoint telemetry for suspicious privilege escalation and activity tied to mounted ISO images.

Share:
Microsoft patches 200 flaws as BitLocker zero-day and Defender RoguePlanet emerge
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Jun 10, 20263d ago

Microsoft condemned uncoordinated zero-day disclosures

Following the RoguePlanet publication, Microsoft publicly criticized uncoordinated disclosures as unjustifiable and risky to customers, while also saying it did not intend to pursue legal action against people merely conducting or publishing security research.

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

June Patch Tuesday fixed MiniPlasma zero-day

On 2026-06-10, Microsoft’s June 2026 Patch Tuesday updates patched MiniPlasma, a publicly disclosed local privilege escalation flaw in the Cloud Files Mini Filter Driver that could grant SYSTEM privileges on fully patched systems. Reporting tied the flaw to researcher Nightmare Eclipse and grouped it with the already noted YellowKey and GreenPlasma disclosures.

Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days

June Patch Tuesday fixed GreenPlasma and YellowKey

Reports on the RoguePlanet disclosure said Microsoft's June 2026 Patch Tuesday updates fixed two earlier flaws, GreenPlasma and YellowKey, previously disclosed by the same researcher. This tied the new disclosure to earlier Defender-related issues addressed in the same patch cycle.

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges

Microsoft disclosed exploited Exchange zero-day CVE-2026-42897

On 2026-06-10, Microsoft identified CVE-2026-42897, an Exchange Server flaw that could enable arbitrary JavaScript execution in a victim’s browser via a crafted email opened in Outlook Web Access under certain conditions, as under active exploitation. The company said a full patch was still in development and that temporary protections were being deployed through the Exchange Emergency Mitigation Service.

Microsoft исправила более 200 уязвимостей и шесть 0-day в своих продуктах - Хакер

Microsoft added MaxHeadersCount mitigation for HTTP2/Bomb abuse

On 2026-06-10, Microsoft introduced a new MaxHeadersCount registry setting while addressing CVE-2026-49160, a publicly disclosed HTTP.sys denial-of-service flaw associated with the HTTP2/Bomb technique. The change was described as a mitigation against header-based HTTP/2 and HTTP/3 abuse.

Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs

Microsoft patched actively exploited Defender flaw CVE-2026-41091

On 2026-06-10, Microsoft’s June 2026 Patch Tuesday updates included a fix for CVE-2026-41091, a Microsoft Defender elevation-of-privilege vulnerability reported as under active exploitation. The flaw had already been added to CISA’s Known Exploited Vulnerabilities catalog, marking it as a significant in-the-wild issue addressed in the release.

Microsoft ships largest Patch Tuesday on record, with one bug under active attack | The Record from Recorded Future News

Microsoft released June 2026 Patch Tuesday fixes

On 2026-06-10, Microsoft released its June 2026 Patch Tuesday updates, fixing 200 vulnerabilities across products including Windows, Office, Azure, Exchange Server, .NET Framework, Hyper-V, Remote Desktop Services, and HTTP.sys. The release included 33 critical flaws and fixes for publicly disclosed issues including CVE-2026-50507.

June 2026 Patch Tuesday Fixes 200 Microsoft Vulnerabilities
Jun 9, 20265d ago

Researcher publicly released RoguePlanet Defender zero-day

On 2026-06-09, security researcher Nightmare Eclipse publicly released the RoguePlanet proof-of-concept exploit targeting a Microsoft Defender race condition that can yield SYSTEM privileges on fully patched Windows 10 and Windows 11 systems. Multiple reports said the exploit was reproduced on patched Windows 11, though it was described as unreliable and not currently working on Windows Server in its present form.

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges

Microsoft disclosed BitLocker zero-day CVE-2026-50507

On 2026-06-09, Microsoft disclosed CVE-2026-50507, a BitLocker security feature bypass vulnerability requiring physical access that could allow unauthorized access to data on affected devices. Microsoft said the flaw had been publicly disclosed before patches were available and that proof-of-concept code existed, though no active exploitation had been observed at release.

Windows BitLocker 0-Day Vulnerability Allow Attackers to Bypass Security Feature

Microsoft hardened Defender in mid-May, blocking some RoguePlanet paths

Nightmare Eclipse said Microsoft changed Defender in mid-May 2026 in a way that blocked some attack paths for the exploit that later became known as RoguePlanet.

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
Jul 9, 202511mo ago

Microsoft patched Brokering File System flaw CVE-2025-49693

Microsoft released a security update for CVE-2025-49693, a local privilege escalation vulnerability in the Microsoft Brokering File System caused by a double free condition that could let an authenticated attacker gain SYSTEM privileges. The update changed memory management behavior to prevent memory from being freed multiple times, and the reference ties detection to systems missing July 2025 update KB5062553.

Microsoft Brokering File System Double Free Vulnerability: A Deep Look into CVE-2025-49693 - ZeroPath Blog | ZeroPath
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

91 LINKEDOpen in app
Vulnerabilities
32 linked
GreenPlasma / Windows Collaborative Translation Framework (CTFMON) Elevation of PrivilegeWindows BitLocker Security Feature Bypass (YellowKey/Bitskrieg)HTTP.sys HTTP/2 Bomb Denial of ServiceRemote Code Execution in Windows HTTP.sysDirty COWDirty PipeCopy FailDirty Frag: Linux kernel xfrm ESP in-place decrypt on shared skb fragsDirty Frag RxRPC Page-Cache Write in Linux kernelFragnesia: Linux kernel skbuff shared-frag marker loss in skb_try_coalesce()Windows Kernel TCP/IP Use-After-Free Remote Code ExecutionYellowKey BitLocker security feature bypass in WindowsMiniPlasma / Elevation of Privilege in Windows Cloud Files Mini Filter DriverBlueHammerRedSun: Microsoft Defender Link-Following Privilege EscalationWindows DHCP Client Service Remote Code Execution VulnerabilityUnDefendCross-Site Scripting in Microsoft Exchange Server Outlook Web AccessRemote Code Execution in Windows Remote Desktop ClientDouble Free Privilege Escalation in Microsoft Brokering File SystemWindows Netlogon Remote Code Execution VulnerabilityInformation Disclosure in Microsoft AuthenticatorArm TLBI completion privilege escalationRCE in Windows Win32K-GRFX via Integer Overflow or WraparoundWindows BitLocker Security Feature BypassSecure Boot bypass in Microsoft-signed UEFI SHIM bootloadersRemote Code Execution in Nuance PowerScribe via Deserialization of Untrusted DataWindows Graphics Component RCE in Win32K GRFXWindows BitLocker Security Feature BypassMicrosoft SharePoint Server Cross-Site Scripting Spoofing VulnerabilityRemote Code Execution in Microsoft Remote Desktop ClientRemote Code Execution in Windows Deployment Services
Threat actors
1 linked
Malware
1 linked
Affected products
28 linked
BitlockerMicrosoft DefenderRemote Desktop ClientLinuxHttp.SysWindows 11Windows 10Windows ServerMicrosoft OfficeWindows BitlockerInternet Information ServicesZoomGoogle MeetGithubApache Http ServerNessusFirefox.Net FrameworkNginxGitlabAndroidWinrarWindows File ExplorerWindows Http.SysWindows Dhcp ClientIosWindows Recovery EnvironmentWindows Collaborative Translation Framework
Organizations
29 linked
Microsoft CorporationTrend MicroTenableThreatLockerGoogleAnthropicAction1MozillaBleepingComputerZoom CommunicationsSnapGitHubThe RegisterLinkedinBlack DuckGitLabCloudflarePicus SecurityDark ReadingXHackread.comFortraThe Cyber ExpressNuance CommunicationsZeropathSecurity AffairsHelp Net SecurityCalifTharros Labs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.