Critical Microsoft Defender Vulnerability Lets Attackers Bypass Security
Key Takeaways A critical zero-day vulnerability, dubbed “RoguePlanet” (CVE-2026-50656), has been identified in Microsoft Defender. The flaw is an Elevation of Privilege (EoP) issue within...
Key Takeaways
- A critical zero-day vulnerability, dubbed “RoguePlanet” (CVE-2026-50656), has been identified in Microsoft Defender.
- The flaw is an Elevation of Privilege (EoP) issue within the Microsoft Malware Protection Engine, allowing local attackers to gain SYSTEM-level access.
- The vulnerability affects fully patched Windows 10 and Windows 11 systems, including those with the June 2026 cumulative updates.
- A functional public proof-of-concept (PoC) exists, and the vulnerability can be exploited even when Defender’s real-time protection is active or in passive mode.
- Microsoft is actively developing a patch, but no release date has been announced.
Microsoft has acknowledged a significant zero-day vulnerability within its Defender security software, publicly named “RoguePlanet.” The company is currently developing a patch to address this critical flaw.
Table Of Content
Vulnerability Details and Impact
Formally documented as CVE-2026-50656, the vulnerability was officially disclosed by the Microsoft Security Response Center (MSRC) on June 16, 2026. It carries a CVSS 3.1 score of 7.8, classifying it as “Important.”
The issue is categorized as an Elevation of Privilege (EoP) vulnerability, stemming from CWE-59: Improper Link Resolution Before File Access (‘Link Following’). This flaw resides within the Microsoft Malware Protection Engine, which is the core scanning component integrated into Microsoft Defender.
According to the CVSS vector string, the vulnerability is locally exploitable, requiring only low privileges and no user interaction. It presents a high impact on confidentiality, integrity, and availability. Significantly, the “Remediation Level” is listed as “Unavailable,” while the “Exploit Code Maturity” is rated “Functional,” confirming the existence of a working public proof-of-concept (PoC).
Discovery and Exploitation
The “RoguePlanet” exploit was first released on June 10, 2026, merely hours after Microsoft completed its June 2026 Patch Tuesday updates. The discovery was made by a security researcher known by the aliases Nightmare Eclipse and Chaotic Eclipse.
The exploit targets a Time-of-Check to Time-of-Use (TOCTOU) race condition within Defender’s real-time scanning engine. It leverages the brief window between when Defender verifies a file path and when it subsequently acts upon it. Successful exploitation results in the spawning of a Windows command prompt with NT AUTHORITYSYSTEM privileges, which represents the highest privilege level available on a Windows system.
Affected Systems and Mitigation Challenges
This vulnerability impacts fully patched Windows 10 and Windows 11 systems, including those that have installed the June 2026 cumulative update, KB5094126. Cybersecurity firm ThreatLocker independently verified the exploit’s viability, successfully reproducing it on fully patched Windows 11 environments.
In a concerning update, Nightmare Eclipse revealed that the PoC functions regardless of whether Defender’s Real-Time Protection is enabled or disabled. It may even operate effectively in passive mode. While the exploit’s reliability can vary across machines due to its race-condition nature, the researcher expressed confidence in its potential for refinement to achieve consistent success rates.
Attempts by the security community to detect or block the PoC using signatures have largely proven ineffective, as minor modifications to the PoC can completely bypass existing mitigations.
Microsoft’s Response
Microsoft has rated this vulnerability as “Exploitation More Likely” on its Exploitability Index, confirming public disclosure but noting that it has not yet been observed being exploited in the wild. The vendor stated, “We are working to provide a high quality security update that addresses this vulnerability.”
Microsoft has not yet announced a specific release date for the patch. The CVE advisory will be updated once the security update becomes available.
What You Should Do
- Monitor official Microsoft channels for the release of a security update addressing CVE-2026-50656.
- Apply the forthcoming patch immediately upon its availability to all affected Windows 10 and Windows 11 systems.
- While awaiting the patch, ensure all other security best practices are rigorously followed, including timely application of non-related security updates and maintaining robust endpoint detection and response (EDR) solutions.
- Given the local exploitation vector, reinforce least privilege principles for all user accounts and restrict access to sensitive system directories where possible.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.