AUTO-UPDATED

Microsoft's patch for a Windows Defender 0-day may have created a new attack path

Microsoft’s recent security patch for the RoguePlanet zero-day vulnerability in Windows Defender is reportedly flawed, potentially allowing attackers to exhaust system storage and disrupt critical operating system functions.

Key Points

  • Security researcher NightmareEclipse identified that the CVE-2026-50656 patch for the Malware Protection Engine (mpengine.dll) remains vulnerable to exploitation.
  • The flaw allows attackers to force Windows Defender to leak data and quarantine large files by abusing the SpyNet cloud service and NTFS Alternate Data Streams.
  • Successful exploitation can fill the system volume, causing erratic behavior in Windows 11 25H2 and Windows Server 2025.
  • The researcher is currently investigating methods to execute this attack remotely without requiring a custom Server Message Block (SMB) server connection.

Why it Matters

This discovery highlights ongoing stability risks within the Windows ecosystem when security patches fail to fully remediate complex zero-day vulnerabilities. If left unaddressed, these flaws could be leveraged to compromise system reliability and create significant operational disruptions for enterprise and individual users.
TechSpot Published by Alfonso Maruccia
Read original