Microsoft's bug-hunting nemesis extends vendetta with more zero-day attacks — Nightmare Eclipse publishes RoguePlanet and GreatXML local privilege escalation exploits

Security smashed
(Image credit: Getty Images)

Ever since appearing on the cybersecurity scene, Nightmare-Eclipse (aka Chaotic-Eclipse) has probably been the largest thorn in the side of the Microsoft Security Response Center. The long-running saga between Redmond and the disgruntled cybersecurity expert got a couple of new chapters this week, thanks to the release of the RoguePlanet and GreatXML exploits.

RoguePlanet is probably the nastiest one, as it takes advantage of yet another vulnerability in Windows Defender to gain SYSTEM user access privileges, letting an attacker execute commands at a privilege level even higher than the standard Administrator. The practical mechanism is simple: just fool a user into running a script, and said script will get full access to the machine, granting the ability to syphon all data, keep exfiltration malware installed, or any other number of malicious activities.

Latest Videos FromTom's Hardware
Bruno Ferreira
Contributor

Bruno Ferreira is a contributing writer for Tom's Hardware. He has decades of experience with PC hardware and assorted sundries, alongside a career as a developer. He's obsessed with detail and has a tendency to ramble on the topics he loves. When not doing that, he's usually playing games, or at live music shows and festivals.

  • DS426
    Popping some more popcorn and laughing at Microslop's recent statement on X. Turns out much of the security community is having a field day with MS over this.

    2061293718942908925View: https://x.com/msftsecresponse/status/2061293718942908925
    Reply
  • JamesJones44
    DS426 said:
    Popping some more popcorn and laughing at Microslop's recent statement on X. Turns out much of the security community is having a field day with MS over this.

    2061293718942908925View: https://x.com/msftsecresponse/status/2061293718942908925
    We did just hear from the Xbox CEO about the need to be "more efficient" and "do more with less". I'm sure this is an MS theme across the board (minus Co-Pilot), so why not do "more with less" and just skip paying security researchers who help improve security and threaten legal action with layers already on the payroll instead? That's "more efficient"
    Reply
  • bigdragon
    JamesJones44 said:
    We did just hear from the Xbox CEO about the need to be "more efficient" and "do more with less". I'm sure this is an MS theme across the board (minus Co-Pilot), so why not do "more with less" and just skip paying security researchers who help improve security and threaten legal action with layers already on the payroll instead? That's "more efficient"
    Brilliant! Microsoft and their competitors already have gamers perform QA on games instead of properly staffing, paying, and allotting time for an internal QA process. They've been adopting a similar approach with Windows over the past couple years too. It'll save even more money to get rid of the paid cybersecurity professionals and crowdsource them from the internet. Just think of all that shareholder cheddar and executive bonuses! Microsoft stock will be going to the moon!
    /sarcasm

    On a more serious note, the Steam Machine can't launch fast enough. I think its success or failure is less important than the impact of introducing a whole new audience to the concept of a PC OS that's not Windows or MacOS. The idea of having a positive experience on Linux is nothing special to readers of Tom's, but it'll be a whole new experience for other people. I don't advocate for a big cybersecurity incident that affects millions of people and I want the next version of Windows to be better, but the antagonistic relationship between Microsoft and Nightmare Eclipse needs to be giving Windows users a lot of anxiety.
    Reply
  • Faiakes
    What an own goal for Microsoft.

    So easy to avoid and yet they are so inept that they let it come down to this.
    Reply