/00 — boot sequence

Hello.

Article

Microsoft Defender RoguePlanet Zero-Day: CVE-2026-50656 Lets Attackers Gain SYSTEM on Fully Patched Windows

July 9, 2026•4 min read
security microsoft defender cve vulnerability windows

Microsoft has quietly patched CVE-2026-50656, a critical local privilege escalation zero-day in Microsoft Defenders Malware Protection Engine that lets attackers gain SYSTEM-level privileges on fully updated Windows 10 and Windows 11 systems. Tracked as "RoguePlanet" by its discoverer, the vulnerability works even when Defenders real-time protection is disabled, making it one of the most concerning Windows security flaws in recent months.

Vulnerability Details

CVE-2026-50656 (CVSS 7.8) resides in mpengine.dll, the core scanning engine that powers Microsoft Defenders malware detection and removal capabilities. The flaw is a race condition that allows an attacker with local access to escalate privileges to SYSTEM, the highest level of access on a Windows machine.

The vulnerability was discovered and responsibly disclosed by security researcher Nightmare-Eclipse (also known as MSNightmare), who published a working proof-of-concept exploit after weeks of intensive development. "Writing this PoC genuinely drained my soul," the researcher noted, describing the challenge of stabilizing the race condition across different system states.

FieldDetails
CVECVE-2026-50656
CVSS Score7.8 (High)
ComponentMicrosoft Malware Protection Engine (mpengine.dll)
Attack VectorLocal, race condition
Privileges GainedSYSTEM
Affected OSWindows 10, Windows 11
FixMalware Protection Engine v1.1.26060.3008

Impact Assessment

The impact of this vulnerability is severe for several reasons:

Bypasses Full Patching. The exploit was successfully tested against fully updated Windows 10 and Windows 11 systems running the June 2026 Patch Tuesday updates. This means organizations that diligently apply every monthly update were still vulnerable.

Works Without Real-Time Protection. Surprisingly, the PoC functions regardless of whether Microsoft Defenders real-time protection is enabled or disabled, and likely works in passive mode too. This dramatically widens the attack surface.

SYSTEM-Level Access. A successful exploit spawns a shell with SYSTEM privileges, giving attackers complete control over the compromised machine.

Fourth Defender Flaw from This Researcher. RoguePlanet is the fourth Microsoft Defender vulnerability reported by Nightmare-Eclipse, following previous flaws that were also patched by Microsoft.

Affected Systems

Any organization running Microsoft Defender on Windows 10 or Windows 11 is potentially affected. The vulnerability does not currently work on Windows Server because standard users cannot mount ISO images, but the researcher states that "the underlying vulnerability still affects server installations and only requires a different exploitation method."

Mitigation and Patching

Microsoft has addressed CVE-2026-50656 in Microsoft Malware Protection Engine version 1.1.26060.3008. The update is distributed automatically through Windows Update for both enterprise and consumer deployments.

Steps to verify your protection status:

  1. Open Windows Security (Windows Security app)
  2. Navigate to Virus and threat protection > Protection updates
  3. Click Check for updates
  4. Verify the engine version is 1.1.26060.3008 or later

To check the engine version programmatically:

powershell

If the version is below 1.1.26060.3008, trigger an immediate update:

powershell

Detection

The RoguePlanet exploit relies on a race condition in the Malware Protection Engines file scanning logic. Security teams should monitor for:

  • Unexpected SYSTEM-level process spawns from low-privilege contexts
  • Repeated crash events in mpengine.dll (potential failed race attempts)
  • Abnormal behavior from the Defender service (WinDefend)

Frequently Asked Questions

Does disabling Microsoft Defender protect me from this vulnerability?

No. The RoguePlanet exploit works regardless of whether real-time protection is enabled or disabled.

Is Windows 11 affected?

Yes, fully updated Windows 11 systems running the June 2026 Patch Tuesday updates are vulnerable.

Is Windows Server affected?

The published PoC does not work on Windows Server in its current form, but the underlying vulnerability exists and may be exploitable with a different technique.

Has this been exploited in the wild?

Microsoft has not confirmed active exploitation, but the availability of a public PoC makes exploitation highly likely in the near term.

Do I need to restart after the update?

The Microsoft Malware Protection Engine update may require a restart depending on whether the engine is currently in use.

Key Takeaways

  • CVE-2026-50656 (RoguePlanet) is a local privilege escalation zero-day in Microsoft Defenders Malware Protection Engine
  • The race condition allows attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows 11
  • Works even with Defender real-time protection disabled
  • Fixed in Malware Protection Engine version 1.1.26060.3008, verify your engine version
  • Public PoC is available, making exploitation by threat actors likely

Conclusion

RoguePlanet serves as a stark reminder that even the software we trust to protect us can be the vector of attack. While Microsoft has patched this specific flaw, the fact that a single researcher has now found four separate privilege escalation bugs in Defenders engine suggests we will see more. Verify your engine version today, and ensure your automatic update pipeline is functioning correctly.


Sources: Security Affairs, BleepingComputer, Microsoft Security Response Center

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links