{"id":13705,"date":"2026-06-18T10:03:50","date_gmt":"2026-06-18T10:03:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/18\/microsoft-confirms-defender-rogueplanet-0-day-exploit-and-working-to-release-patch\/"},"modified":"2026-06-18T10:03:50","modified_gmt":"2026-06-18T10:03:50","slug":"microsoft-confirms-defender-rogueplanet-0-day-exploit-and-working-to-release-patch","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/18\/microsoft-confirms-defender-rogueplanet-0-day-exploit-and-working-to-release-patch\/","title":{"rendered":"Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch"},"content":{"rendered":"<p>    Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, <a href=\"https:\/\/cybersecuritynews.com\/windows-defender-0-day-exploit-rogueplanet\/\" target=\"_blank\" rel=\"noreferrer noopener\">publicly dubbed \u201cRoguePlanet,\u201d<\/a> and confirmed it is actively developing a security patch to address the flaw.<\/p>\n<p class=\"wp-block-paragraph\">Tracked as CVE-2026-50656, the vulnerability was formally published on June 16, 2026, by the Microsoft Security Response Center (MSRC) and carries a CVSS score of 7.8 (Important) under the CVSS 3.1 scoring framework.<\/p>\n<p class=\"wp-block-paragraph\">The flaw is classified as an Elevation of Privilege (EoP) vulnerability rooted in CWE-59: Improper Link Resolution Before File Access (\u2018Link Following\u2019), affecting the Microsoft Malware Protection Engine, the core scanning component embedded in Microsoft Defender.<\/p>\n<p class=\"wp-block-paragraph\">The CVSS vector string  reflects a locally exploitable flaw requiring only low privileges and no user interaction, with high impact across confidentiality, integrity, and availability. Notably, the Remediation Level is listed as Unavailable, and the Exploit Code Maturity is rated Functional, confirming that a working public proof-of-concept (PoC) exists.<\/p>\n<p class=\"wp-block-paragraph\">RoguePlanet was first released on June 10, 2026, just hours after Microsoft concluded its <a href=\"https:\/\/cybersecuritynews.com\/microsoft-patch-tuesday-june-2026\/\" target=\"_blank\" rel=\"noreferrer noopener\">June 2026 Patch Tuesday<\/a> rollout by a security researcher operating under the aliases Nightmare Eclipse and Chaotic Eclipse.<\/p>\n<p class=\"wp-block-paragraph\">The exploit targets a Time-of-Check to Time-of-Use (TOCTOU) race condition within Defender\u2019s real-time scanning engine, exploiting the brief timing window between when Defender verifies a file path and when it acts on it. When successfully triggered, the exploit spawns a Windows command prompt running as NT AUTHORITYSYSTEM the highest privilege level on a Windows machine.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability affects fully patched Windows 10 and Windows 11 systems, including those running the June 2026 cumulative update KB5094126. Cybersecurity firm ThreatLocker independently reproduced the exploit and confirmed its viability on fully patched Windows 11 systems.<\/p>\n<p class=\"wp-block-paragraph\">In a particularly alarming update, Nightmare Eclipse <a href=\"https:\/\/blog.projectnightcrawler.dev\/posts\/2026-06-16-rogueplanet-another-quick-statement\/\" target=\"_blank\" rel=\"noreferrer noopener\">revealed that the PoC works<\/a> regardless of whether Defender\u2019s Real-Time Protection is enabled or disabled and may even function in passive mode. The exploit\u2019s reliability varies by machine due to its race-condition nature, but the researcher expressed confidence that it can be refined to achieve consistent success rates.<\/p>\n<p class=\"wp-block-paragraph\">Attempts by the security community to detect or block the PoC through signatures have proven largely ineffective, as minor modifications to the PoC can bypass mitigations entirely.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft has rated this vulnerability \u201cExploitation More Likely\u201d on its Exploitability Index, with public disclosure confirmed and the vulnerability not yet observed being exploited in the wild. The vendor stated: \u201cWe are working to provide a high quality security update that addresses this vulnerability.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-50656\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft has not yet announced<\/a> a specific patch release date, and the CVE advisory will be updated once the security update becomes available.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/defender-rogueplanet-0-day-exploit-patch\/\">Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/defender-rogueplanet-0-day-exploit-patch\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed \u201cRoguePlanet,\u201d and confirmed it is actively developing a security patch to address the flaw. Tracked as CVE-2026-50656, the vulnerability was formally published on June 16, 2026, by the Microsoft Security Response [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-13705","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13705"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13705"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13705\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}