Elevation of Privilege in Microsoft Defender by Microsoft
CVE-2026-50656
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 16 June 2026
Badges
What is CVE-2026-50656?
CVE-2026-50656 is a significant vulnerability identified within the Microsoft Malware Protection Engine, a crucial component of the Microsoft Defender security suite designed to protect systems from various forms of malware and cyber threats. This vulnerability constitutes an elevation of privilege, which may allow an attacker to gain unauthorized access to system resources or escalate their user permissions without proper authorization. If exploited, this can severely weaken an organization's security posture, allowing malicious actors to execute arbitrary code, compromise sensitive data, or manipulate system operations, potentially leading to widespread impact across affected installations.
Potential impact of CVE-2026-50656
-
Unauthorized Access: This vulnerability could enable attackers to gain higher privileges on the system, overriding existing security measures and allowing them to access sensitive system files and data that would typically be protected.
-
Malware Deployment: By elevating their privileges, adversaries could deploy additional malware or ransomware, further compromising the integrity of the systems and potentially leading to significant data loss or theft.
-
Operational Disruption: The exploitation of this vulnerability could result in service outages or system malfunctions, impacting an organization's operations and service delivery, and leading to potential financial losses and reputational damage.
Affected Version(s)
Microsoft Malware Protection Engine 1.1.0.0 < 1.1.26060.3008
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Microsoft Reins in RoguePlanet Zero-Day Threat
The researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June.
3 weeks ago
Defender Zero-Day Patched 29 Days After Public Exploit Exposed Millions of PCs
Windows Defender zero-day CVE-2026-50656 — known as RoguePlanet — has been patched by Microsoft 29 days after researcher Nightmare Eclipse published working exploit code granting SYSTEM-level access
3 weeks ago
Microsoft Releases Patch for RoguePlanet Defender Zero-Day Vulnerability
Microsoft has released security updates for the RoguePlanet zero-day vulnerability in Microsoft Defender.
3 weeks ago

References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 💰
Used in Ransomware
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by Onmsft
Vulnerability published
Vulnerability Reserved