AUTO-UPDATED

A critical exploit bypasses Microsoft Defender in Windows 11 and Windows 10 — so much for "everyday risk protection without additional software"

Security researcher Nightmare-Eclipse has disclosed a new zero-day vulnerability named RoguePlanet affecting Microsoft Defender, prompting Microsoft to track the flaw as CVE-2026-50656 while developing a security patch.

Key Points

  • The RoguePlanet exploit allows attackers to gain full system control by leveraging an elevation of privilege in the Microsoft Malware Protection Engine.
  • Microsoft previously addressed three other zero-day exploits discovered by the researcher, identified as YellowKey, GreenPlasma, and MiniPlasma.
  • The researcher published a proof-of-concept for the vulnerability in a self-hosted Git repository after Microsoft allegedly removed previous exploit disclosures from GitHub and GitLab.
  • Microsoft has officially confirmed the vulnerability and is currently working on a high-quality security update to mitigate the risk for Windows 10 and 11 users.
  • Following community backlash, Microsoft has abandoned plans to pursue legal action against security researchers who publish findings regarding their software vulnerabilities.

Why it Matters

This discovery challenges Microsoft's long-standing position that its built-in Defender software provides sufficient protection for the average Windows user. The incident highlights ongoing tensions between independent security researchers and major tech corporations regarding the disclosure and remediation of critical system vulnerabilities.
Windows Central Published by kevinokemwa@outlook.com (Kevin Okemwa) , Kevin Okemwa
Read original