Vulnerabilities · 89 days ago
BitLocker Trust Break Follows Defender Offline Scan A current patch level does not stop this one if Defender Offline Scan was ever used. GreatXML turns that setup step into a lasting trust break in WinRE, so a patched Windows 10 or 11 desktop can still expose BitLocker-protected data after a reboot into Recovery Mode.
The public PoC plants XML state on the recovery partition and relies on WinRE trusting the offline-scan artifacts Defender left behind. Microsoft Defender offline scan and Windows Recovery Environment are the pieces in play here, and the result is unrestricted access to the protected volume without the BitLocker key.
That shifts the story from a local SYSTEM-shell bug to a BitLocker bypass on systems that look healthy on paper. The risk persists anywhere recovery modes or other trusted-on-disk state can be rewritten and later honored by the boot environment.
NVD KEV
Known exploited · CISA KEV
CVSS 7.8 HIGH: improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to… EPSS 9% (93rd percentile). Microsoft patch: Release Notes.
CISA federal remediation date Jun 3 · date passed
NVD KEV
Known exploited · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Microsoft patch: Release Notes.
CISA federal remediation date May 6 · date passed
Timeline Sources 9 sources covering this story
The Hacker News Jun 17
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Microsoft is preparing a patch for RoguePlanet, a Defender flaw tracked as CVE-2026-50656 that can enable privilege escalation.
Help Net Security Jun 17
Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) - Help Net Security
Microsoft has acknowledged the elevation of privilege Microsoft Defender bug (CVE-2026-50656) triggered via the "RoguePlanet" exploit.
SecurityWeek Jun 17
Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day
The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.
BleepingComputer Jun 17
Microsoft working on Defender patch for RoguePlanet zero-day
Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago.
Risky Biz News Jun 12
Risky Bulletin: CISA tightens patching rules amid bug deluge
CISA changes federal patching rules due to AI, a House Republican was hacked by Russia, ShinyHunters go on an Oracle hacking spree, and np [Read More
The Hacker News Jun 11
New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
GreatXML can bypass BitLocker on Windows systems where Defender Offline Scan was used, exposing encrypted drive data.
SecurityWeek Jun 11
‘GreatXML’ Zero-Day Exploit Bypasses BitLocker
The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode.
SecurityWeek Jun 11
Microsoft Patches Exploited Exchange Server Vulnerability
The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14.
Dark Reading Jun 10
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
The disgruntled researcher released a PoC for a Windows Defender bug that allows for system takeover, showing no sign of abandoning their ongoing feud.
BleepingComputer Jun 10
Microsoft patches Exchange Server zero-day exploited in attacks
Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users.
SecurityWeek Jun 10
New Windows Zero-Day Exploit ‘RoguePlanet’ Released
Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.
The Hacker News Jun 10
Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Microsoft released fixes for 206 vulnerabilities across its software portfolio, including 39 Critical flaws and three publicly disclosed zero-days.
Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-06-09
Editions Related stories
Vulnerabilities · 89 days ago
BitLocker Trust Break Follows Defender Offline Scan A current patch level does not stop this one if Defender Offline Scan was ever used. GreatXML turns that setup step into a lasting trust break in WinRE, so a patched Windows 10 or 11 desktop can still expose BitLocker-protected data after a reboot into Recovery Mode.
The public PoC plants XML state on the recovery partition and relies on WinRE trusting the offline-scan artifacts Defender left behind. Microsoft Defender offline scan and Windows Recovery Environment are the pieces in play here, and the result is unrestricted access to the protected volume without the BitLocker key.
That shifts the story from a local SYSTEM-shell bug to a BitLocker bypass on systems that look healthy on paper. The risk persists anywhere recovery modes or other trusted-on-disk state can be rewritten and later honored by the boot environment.
NVD KEV
Known exploited · CISA KEV
CVSS 7.8 HIGH: improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to… EPSS 9% (93rd percentile). Microsoft patch: Release Notes.
CISA federal remediation date Jun 3 · date passed
NVD KEV
Known exploited · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Microsoft patch: Release Notes.
CISA federal remediation date May 6 · date passed
Timeline Sources 9 sources covering this story
The Hacker News Jun 17
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Microsoft is preparing a patch for RoguePlanet, a Defender flaw tracked as CVE-2026-50656 that can enable privilege escalation.
Help Net Security Jun 17
Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) - Help Net Security
Microsoft has acknowledged the elevation of privilege Microsoft Defender bug (CVE-2026-50656) triggered via the "RoguePlanet" exploit.
SecurityWeek Jun 17
Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day
The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.
BleepingComputer Jun 17
Microsoft working on Defender patch for RoguePlanet zero-day
Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago.
Risky Biz News Jun 12
Risky Bulletin: CISA tightens patching rules amid bug deluge
CISA changes federal patching rules due to AI, a House Republican was hacked by Russia, ShinyHunters go on an Oracle hacking spree, and np [Read More
The Hacker News Jun 11
New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
GreatXML can bypass BitLocker on Windows systems where Defender Offline Scan was used, exposing encrypted drive data.
SecurityWeek Jun 11
‘GreatXML’ Zero-Day Exploit Bypasses BitLocker
The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode.
SecurityWeek Jun 11
Microsoft Patches Exploited Exchange Server Vulnerability
The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14.
Dark Reading Jun 10
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
The disgruntled researcher released a PoC for a Windows Defender bug that allows for system takeover, showing no sign of abandoning their ongoing feud.
BleepingComputer Jun 10
Microsoft patches Exchange Server zero-day exploited in attacks
Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users.
SecurityWeek Jun 10
New Windows Zero-Day Exploit ‘RoguePlanet’ Released
Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.
The Hacker News Jun 10
Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Microsoft released fixes for 206 vulnerabilities across its software portfolio, including 39 Critical flaws and three publicly disclosed zero-days.
Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-06-09
Editions Related stories