AUTO-UPDATED

Microsoft Confirms RoguePlanet Zero-Day in Defender, Patch Under Development

Microsoft has acknowledged a zero-day vulnerability in the Microsoft Malware Protection Engine, tracked as CVE-2026-50656, which allows attackers to gain SYSTEM-level privileges on Windows 10 and 11 systems.

Key Points

  • The vulnerability, dubbed RoguePlanet, carries a CVSS score of 7.8 and exploits a race condition within Microsoft Defender.
  • Security researcher Chaotic Eclipse published a proof-of-concept exploit that functions even on fully updated Windows systems.
  • Microsoft is currently developing a security update to address the flaw and is investigating the researcher's claims of additional memory corruption issues.
  • The exploit currently affects Windows 10 and 11, though the researcher suggests the underlying vulnerability may also impact Windows Server installations.
  • This disclosure follows a series of public zero-day releases by the same researcher, including vulnerabilities named YellowKey, GreenPlasma, and RedSun.

Why it Matters

The public release of functional exploit code creates an immediate security risk for users by allowing attackers to bypass standard protections before a patch is available. This incident highlights the ongoing tension between independent security researchers and Microsoft regarding the company's coordinated vulnerability disclosure and bug bounty processes.
Securityaffairs.com Published by Pierluigi Paganini
Read original