HomeUpdatesRoguePlanet: Microsoft patches critical Defender vulnerability

RoguePlanet: Microsoft patches critical Defender vulnerability

Microsoft has released security updates for the RoguePlanet, which was discovered in Microsoft Defender and could allow an attacker to gain full SYSTEM-level privileges. The fix comes nearly a month after the vulnerability was publicly disclosed, which raised concerns in the cybersecurity community. The issue affects millions of Windows worldwide, as Microsoft Defender is the default antivirus solution for the operating system.

RoguePlanet vulnerability Microsoft Defender CVE-2026-50656 SYSTEM privileges

The vulnerability is tracked as CVE-2026-50656 and has a CVSS score of 7.8. It is a privilege escalation located in the Microsoft Malware Protection Engine — also known as mpengine.dll — which is the core of the scanning, detection, and threat neutralization functions for the company's antivirus and antispyware software. The severity of the vulnerability lies in the fact that it affects the very tool that is supposed to protect the system.

See also: RoguePlanet Zero-Day: New Microsoft Defender vulnerability gives SYSTEM access

Microsoft announced that the issue has been addressed in version 1.1.26060.3008 of the Microsoft Malware Protection Engine , while defense-in-depth updates to strengthen non-specific security features have also been released . According to the company, no action is required from users to install the update, as the software updates automatically.

What is RoguePlanet and how does the vulnerability work?

RoguePlanet was first discovered by security researcher Chaotic Eclipse (aka Nightmare-Eclipse), who described it as a race conditionthat can be exploited to create a shell with SYSTEM. This allows an attacker to execute code or perform unauthorized actions on the target system. A race condition occurs when two or more processes attempt to access a shared resource at the same time, and the outcome depends on the order in which they execute — something that an attacker can exploit.

RoguePlanet - SecNews.gr

Particularly concerning is the fact that the exploit works on systems running updated versions of Windows (Patch Tuesday June 2026). Furthermore, Chaotic Eclipse revealed that the exploit works regardless of whether real-time protection is enabled — which makes the vulnerability even more dangerous. It is worth noting that Microsoft has not officially acknowledged Chaotic Eclipse as the researcher who discovered the vulnerability.

RoguePlanet: The fourth Defender vulnerability from the same researcher

RoguePlanet is not the first vulnerability that Chaotic Eclipse has disclosed in Microsoft Defender. It is the fourth in a row, following BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498), and RedSun (CVE-2026-41091), which have already been patched by Microsoft. The fact that a single researcher has found four serious vulnerabilities in the same product raises questions about the overall security of Microsoft's Malware Protection Engine and the company's code review processes.

See also: Microsoft confirms RoguePlanet Defender zero-day – Preparing patch

The sequence of these revelations highlights the importance of independent security research and responsible disclosure. However, the nearly month-long delay between public disclosure and official patch is a point of concern, as malicious actors could exploit the vulnerability. Microsoft has not disclosed whether there were any actual attacks exploiting CVE-2026-50656 before the patch was released.

RoguePlanet vulnerability Microsoft Defender zero-day exploit

According to The Hacker News, Microsoft clarified that for both enterprise deployments and end users, the default configuration of antimalware software ensures that malware definitions and the Microsoft Malware Protection Engine are updated automatically. Depending on which antimalware software is used and how it is configured, the software may check for engine and definition updates every day when it is connected to the internet (even multiple times a day).

For users who wish to verify that their system is protected, it is recommended to manually check for updates via Windows Security or Microsoft Defender. The Microsoft Malware Protection Engine must be at least 1.1.26060.3008 to be protected from RoguePlanet. Additionally, system administrators in corporate environments should ensure that automatic update policies are enabled on all endpoints.

See also: CISA: Ransomware gangs exploit Microsoft Defender's BlueHammer vulnerability

In conclusion, the RoguePlanet vulnerability is a reminder that even the security tools we use to protect ourselves can contain critical vulnerabilities. Promptly applying security updates, monitoring official Microsoft announcements, and maintaining an up-to-date Microsoft Defender remain the most effective defense practices for every user and organization.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS