Microsoft has released security updates to address a critical privilege escalation vulnerability in its Microsoft Malware Protection Engine, tracked as CVE-2026-50656 (CVSS 7.8). Dubbed ‘RoguePlanet’ by the researcher who discovered it, the flaw resides in mpengine.dll and can be exploited to grant SYSTEM-level privileges to an attacker, enabling arbitrary code execution and unauthorized actions.
The vulnerability was publicly disclosed by security researcher Chaotic Eclipse (aka Nightmare-Eclipse), who described it as a race condition that works even on fully patched Windows systems with the June 2026 Patch Tuesday updates installed. Notably, the exploit functions regardless of whether real-time protection is enabled or disabled. Microsoft has not officially credited the researcher for the discovery.
RoguePlanet is the fourth Defender vulnerability disclosed by Chaotic Eclipse, following BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498), and RedSun (CVE-2026-41091), all of which have been patched. The fix is included in Microsoft Malware Protection Engine version 1.1.26060.3008, along with defense-in-depth updates. Microsoft stated that no customer action is required for installation, as the engine updates automatically for most users and enterprise deployments.
CVEs: CVE-2026-50656, CVE-2026-33825, CVE-2026-45498, CVE-2026-41091, CVE-2026-55200, CVE-2026-46817
Companies: Microsoft
Products: Microsoft Malware Protection Engine, Microsoft Defender
Original source: thehackernews.com