Skip to main content

Microsoft Confirms Work on Patch for Critical Defender Zero-Day ‘RoguePlanet’

Microsoft has confirmed that it is developing a security update for RoguePlanet, a newly disclosed zero-day vulnerability affecting Microsoft Defender on fully patched Windows 10 and Windows 11 systems.

The flaw, tracked as CVE-2026-50656, was publicly disclosed by the security researcher known as “Nightmare Eclipse,” who also released a proof-of-concept exploit demonstrating how attackers could potentially gain full system privileges.

What Is RoguePlanet?

RoguePlanet is an elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine, the core scanning engine used by Microsoft Defender.

According to the researcher, the flaw stems from a race condition that can be exploited to launch a command prompt with SYSTEM-level privileges, giving an attacker complete control over the affected computer.

The exploit reportedly affects systems that are already fully updated, making it particularly significant.

Proof-of-Concept Exploit Released

Nightmare Eclipse published a proof-of-concept exploit in a self-hosted Git repository after claiming that previous exploit repositories hosted on GitHub and GitLab had been removed.

The researcher notes that exploitation is not guaranteed on every attempt due to the race-condition nature of the vulnerability:

“The exploit is a race condition, so it’s a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others.”

Although reliability varies between systems, the exploit demonstrates that successful privilege escalation is possible under the right conditions.

Microsoft Responds

In a statement to BleepingComputer, Microsoft acknowledged the vulnerability and confirmed that a fix is currently in development:

“Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘RoguePlanet.’ We are working to provide a high-quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.”

The company has not announced an exact release date for the security update.

Part of a Series of Vulnerability Disclosures

RoguePlanet is the latest in a string of Windows security vulnerabilities disclosed by Nightmare Eclipse.

In recent months, the researcher has also published technical details for several other vulnerabilities, including:

  • BlueHammer
  • RedSun
  • MiniPlasma
  • YellowKey

The disclosures have drawn attention to multiple components within Windows and Microsoft’s security ecosystem.

Users Should Await the Official Patch

Until Microsoft releases a fix, there is no official mitigation that completely eliminates the vulnerability.

Users are advised to continue installing Windows and Microsoft Defender updates as soon as they become available and to follow standard security best practices, including avoiding untrusted software and limiting administrative access, while waiting for Microsoft’s official patch for CVE-2026-50656.