Microsoft Patches RoguePlanet Defender Elevation-of-Privilege Flaw

Microsoft Patches RoguePlanet Defender Elevation-of-Privilege Flaw


Microsoft has shipped the fix, closing out a vulnerability that’s been live since June 10.

What happened: Microsoft addressed the RoguePlanet vulnerability by releasing Microsoft Malware Protection Engine 1.1.26060.3008, an update to the core scanning engine that powers its security solutions and services

The flaw: CVE-2026-50656 (CVSS 7.8) is a privilege escalation issue in the Microsoft Malware Protection Engine (mpengine.dll), which handles scanning, detection, and cleaning for Defender and related antimalware products . It stems from improper link resolution before file access (CWE-59) and can be exploited in low-complexity attacks by authenticated attackers with no user interaction required.

Exploitation mechanics: The flaw affects fully patched Windows 10 and Windows 11 devices, letting attackers spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition . The researcher behind it, going by “Nightmare Eclipse”/”Chaotic Eclipse,” shared a PoC in a self-hosted Git repo, claiming Microsoft had previously removed their exploit repos from GitHub and GitLab. Notably, the exploit works on systems fully patched with June 2026 Patch Tuesday updates, and functions regardless of whether real-time protection is enabled .

Affected/fixed versions: Versions before 1.1.26060.3008 are vulnerable; systems on 1.1.26050.11 or earlier are at risk. The Malware Protection Engine underpins Defender Antivirus, Security Essentials, and System Center Endpoint Protection — a broad enterprise and consumer footprint.

Patch details: The fix includes defense-in-depth hardening to unspecified security-related features beyond the core patch. No customer action is required — the engine updates automatically under default configuration . Still worth verifying: security teams should confirm endpoints show version 1.1.26060.3008 or later, given the low attack complexity and no user-interaction requirement.

Context: This is the fourth Defender vulnerability from this researcher, following BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498), and RedSun (CVE-2026-41091) — all now patched . No in-the-wild exploitation was detected, though Microsoft rated it “Exploitation More Likely” .

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.