Microsoft has formally disclosed a zero-day vulnerability in Microsoft Defender, codenamed RoguePlanet, and confirmed that a patch is in development. The flaw, assigned CVE-2026-50656 with a CVSS score of 7.8, is an elevation of privilege vulnerability in the Microsoft Malware Protection Engine.
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) publicly released the exploit, describing it as a race condition that can grant attackers a shell with SYSTEM-level privileges. The researcher noted that the proof-of-concept works regardless of whether real-time protection is enabled, and may also function in passive mode.
RoguePlanet is the fourth Defender vulnerability disclosed by Chaotic Eclipse, following BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498), and RedSun (CVE-2026-41091), all of which have been patched by Microsoft. The company is actively working on a security update to address this latest issue.
CVEs: CVE-2026-50656, CVE-2026-33825, CVE-2026-45498, CVE-2026-41091, CVE-2026-11645
Companies: Microsoft
Products: Microsoft Defender, Microsoft Malware Protection Engine
Original source: thehackernews.com