Security researcher Nightmare-Eclipse has disclosed a new zero-day vulnerability named RoguePlanet affecting Microsoft Defender, prompting Microsoft to track the flaw as CVE-2026-50656 while developing a security patch.
Key Points
- The RoguePlanet exploit allows attackers to gain full system control by leveraging an elevation of privilege in the Microsoft Malware Protection Engine.
- Microsoft previously addressed three other zero-day exploits discovered by the researcher, identified as YellowKey, GreenPlasma, and MiniPlasma.
- The researcher published a proof-of-concept for the vulnerability in a self-hosted Git repository after Microsoft allegedly removed previous exploit disclosures from GitHub and GitLab.
- Microsoft has officially confirmed the vulnerability and is currently working on a high-quality security update to mitigate the risk for Windows 10 and 11 users.
- Following community backlash, Microsoft has abandoned plans to pursue legal action against security researchers who publish findings regarding their software vulnerabilities.