Microsoft rolls out Defender patch for RoguePlanet flaw

Microsoft began rolling out a patch for Defender vulnerability RoguePlanet (CVE-2026-50656) via an automatic Microsoft Malware Protection Engine update. A proof-of-concept exploit was published June 9.

Microsoft has begun distributing a patch for a Defender vulnerability tracked as CVE-2026-50656, nicknamed RoguePlanet. The fix was delivered through an update to the Microsoft Malware Protection Engine after a proof-of-concept exploit was published on June 9. The flaw exploits a race condition that can allow an attacker to elevate a process to the System account.

Microsoft published an advisory for the vulnerability on June 16 and updated that guidance on July 8 to announce that fixes were available. The company wrote that customers do not need to take action because the Microsoft Malware Protection Engine update is designed to deploy automatically to devices running Defender. Microsoft also noted the engine update includes unspecified defense-in-depth updates to improve security-related features.

The proof-of-concept was posted by a researcher who uses the names Nightmare Eclipse and Chaotic Eclipse. The researcher reported the exploit did not achieve a 100% success rate in testing but could be redesigned to improve stability. The researcher previously disclosed other Windows vulnerabilities that were later observed exploited in the wild, including RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498) and BlueHammer (CVE-2026-33825).

After Microsoft began the patch rollout, the researcher performed additional analysis of Defender and reported finding potential issues involving memory leaks and the handling of quarantined files. The researcher is examining whether those findings can be turned into reliable exploits.

There have been no public reports of RoguePlanet being used in attacks to date. Organizations that keep Defender’s automatic updates enabled should receive the engine update without manual intervention. System administrators who manage updates centrally or who have disabled automatic updates are advised to verify that the Microsoft Malware Protection Engine update containing the patch has been applied.

Microsoft’s advisory timeline — proof-of-concept published June 9, advisory on June 16 and an update on July 8 announcing patch availability — shows the sequence of public disclosure and the company’s subsequent guidance. Independent analysis of the patched engine is ongoing and may prompt additional updates if new issues are confirmed.

Articles by this author