Microsoft’s recent security patch for the RoguePlanet zero-day vulnerability in Windows Defender is reportedly flawed, potentially allowing attackers to exhaust system storage and disrupt critical operating system functions.
Key Points
- Security researcher NightmareEclipse identified that the CVE-2026-50656 patch for the Malware Protection Engine (mpengine.dll) remains vulnerable to exploitation.
- The flaw allows attackers to force Windows Defender to leak data and quarantine large files by abusing the SpyNet cloud service and NTFS Alternate Data Streams.
- Successful exploitation can fill the system volume, causing erratic behavior in Windows 11 25H2 and Windows Server 2025.
- The researcher is currently investigating methods to execute this attack remotely without requiring a custom Server Message Block (SMB) server connection.