Microsoft has quietly patched CVE-2026-50656, a critical local privilege escalation zero-day in Microsoft Defenders Malware Protection Engine that lets attackers gain SYSTEM-level privileges on fully updated Windows 10 and Windows 11 systems. Tracked as "RoguePlanet" by its discoverer, the vulnerability works even when Defenders real-time protection is disabled, making it one of the most concerning Windows security flaws in recent months.
Vulnerability Details
CVE-2026-50656 (CVSS 7.8) resides in mpengine.dll, the core scanning engine that powers Microsoft Defenders malware detection and removal capabilities. The flaw is a race condition that allows an attacker with local access to escalate privileges to SYSTEM, the highest level of access on a Windows machine.
The vulnerability was discovered and responsibly disclosed by security researcher Nightmare-Eclipse (also known as MSNightmare), who published a working proof-of-concept exploit after weeks of intensive development. "Writing this PoC genuinely drained my soul," the researcher noted, describing the challenge of stabilizing the race condition across different system states.
| Field | Details |
|---|---|
| CVE | CVE-2026-50656 |
| CVSS Score | 7.8 (High) |
| Component | Microsoft Malware Protection Engine (mpengine.dll) |
| Attack Vector | Local, race condition |
| Privileges Gained | SYSTEM |
| Affected OS | Windows 10, Windows 11 |
| Fix | Malware Protection Engine v1.1.26060.3008 |
Impact Assessment
The impact of this vulnerability is severe for several reasons:
Bypasses Full Patching. The exploit was successfully tested against fully updated Windows 10 and Windows 11 systems running the June 2026 Patch Tuesday updates. This means organizations that diligently apply every monthly update were still vulnerable.
Works Without Real-Time Protection. Surprisingly, the PoC functions regardless of whether Microsoft Defenders real-time protection is enabled or disabled, and likely works in passive mode too. This dramatically widens the attack surface.
SYSTEM-Level Access. A successful exploit spawns a shell with SYSTEM privileges, giving attackers complete control over the compromised machine.
Fourth Defender Flaw from This Researcher. RoguePlanet is the fourth Microsoft Defender vulnerability reported by Nightmare-Eclipse, following previous flaws that were also patched by Microsoft.
Affected Systems
Any organization running Microsoft Defender on Windows 10 or Windows 11 is potentially affected. The vulnerability does not currently work on Windows Server because standard users cannot mount ISO images, but the researcher states that "the underlying vulnerability still affects server installations and only requires a different exploitation method."
Mitigation and Patching
Microsoft has addressed CVE-2026-50656 in Microsoft Malware Protection Engine version 1.1.26060.3008. The update is distributed automatically through Windows Update for both enterprise and consumer deployments.
Steps to verify your protection status:
- Open Windows Security (Windows Security app)
- Navigate to Virus and threat protection > Protection updates
- Click Check for updates
- Verify the engine version is 1.1.26060.3008 or later
To check the engine version programmatically:
If the version is below 1.1.26060.3008, trigger an immediate update:
Detection
The RoguePlanet exploit relies on a race condition in the Malware Protection Engines file scanning logic. Security teams should monitor for:
- Unexpected SYSTEM-level process spawns from low-privilege contexts
- Repeated crash events in
mpengine.dll(potential failed race attempts) - Abnormal behavior from the Defender service (WinDefend)
Frequently Asked Questions
Does disabling Microsoft Defender protect me from this vulnerability?
No. The RoguePlanet exploit works regardless of whether real-time protection is enabled or disabled.
Is Windows 11 affected?
Yes, fully updated Windows 11 systems running the June 2026 Patch Tuesday updates are vulnerable.
Is Windows Server affected?
The published PoC does not work on Windows Server in its current form, but the underlying vulnerability exists and may be exploitable with a different technique.
Has this been exploited in the wild?
Microsoft has not confirmed active exploitation, but the availability of a public PoC makes exploitation highly likely in the near term.
Do I need to restart after the update?
The Microsoft Malware Protection Engine update may require a restart depending on whether the engine is currently in use.
Key Takeaways
- CVE-2026-50656 (RoguePlanet) is a local privilege escalation zero-day in Microsoft Defenders Malware Protection Engine
- The race condition allows attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows 11
- Works even with Defender real-time protection disabled
- Fixed in Malware Protection Engine version 1.1.26060.3008, verify your engine version
- Public PoC is available, making exploitation by threat actors likely
Conclusion
RoguePlanet serves as a stark reminder that even the software we trust to protect us can be the vector of attack. While Microsoft has patched this specific flaw, the fact that a single researcher has now found four separate privilege escalation bugs in Defenders engine suggests we will see more. Verify your engine version today, and ensure your automatic update pipeline is functioning correctly.
Sources: Security Affairs, BleepingComputer, Microsoft Security Response Center
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.