Microsoft Acknowledges 'RoguePlanet' Defender Zero-Day, Patch Still in the Works

CVE-2026-50656 is a privilege escalation bug in the Malware Protection Engine, the component sitting at the heart of every Defender install.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Microsoft Acknowledges 'RoguePlanet' Defender Zero-Day, Patch Still in the Works
Share

Key points

  • Microsoft has confirmed an unpatched elevation-of-privilege flaw in the Microsoft Malware Protection Engine, tracked as CVE-2026-50656 (CVSS 7.8).
  • The flaw is internally codenamed RoguePlanet; a fix is in development and will ship via the engine's automatic update channel.
  • Enterprise admins who block or delay engine updates will need to act before the fix arrives.
  • Microsoft has not confirmed active exploitation or published affected engine version numbers.
  • A public proof-of-concept already exists: we reported its release on 10 June in RoguePlanet PoC Drops: Another Defender Race Condition, Another Path to SYSTEM.

Microsoft has confirmed an unpatched elevation-of-privilege flaw in the Microsoft Malware Protection Engine, the scanning core that ships with every supported version of Defender. The bug, tracked as CVE-2026-50656, carries a CVSS score of 7.8 and is internally codenamed RoguePlanet.

No patch yet. The fix is in development and will roll out through the Malware Protection Engine's automatic update channel rather than the monthly cumulative cycle. That matters: the engine updates itself silently in most environments, which is why Microsoft historically resolves engine flaws without a Patch Tuesday entry. Admins who block or delay engine updates will need to revisit those policies before the fix lands.

What the flaw does

Microsoft describes RoguePlanet as a local elevation of privilege. A CVSS 7.8 score at that vector typically means a low-privileged attacker already on the machine can escalate to SYSTEM by abusing a component Defender runs with high privileges. Microsoft has not published exploitation details or a list of affected engine versions.

Microsoft has not said whether the flaw is being exploited in the wild. "Zero-day" here means disclosed before a fix shipped, not confirmed active abuse. A public proof-of-concept is already circulating: an anonymous researcher publishing as Chaotic Eclipse dropped it, and we covered that release on 10 June. That shortens the risk window considerably.

Defender variants sharing the engine, including Defender for Endpoint, Defender Antivirus on Windows 10 and Windows 11, Defender on Server editions, and Defender for Business, are all in scope until Microsoft narrows the list.

Should you worry?

Yes, if your organisation pins or delays engine updates. The fixed build will not arrive through WSUS (Windows Server Update Services, the standard enterprise patch distribution tool) in the usual sense. It comes through the engine's own update path. Confirm that Malware Protection Engine auto-updates are enabled, then audit any Group Policy or MDM (mobile device management) setting that locks engine versions.

Watch the MSRC advisory for the engine build number containing the fix, and verify rollout using Get-MpComputerStatus: the AMEngineVersion field shows what version is running on each machine.

No regulator action is tied to this yet. An engine-level fix that ships automatically is the cleanest case Microsoft's update mechanism handles. The real exposure is the gap between disclosure and the patched engine build reaching every machine in your fleet, and with a working proof-of-concept already public, that gap deserves attention now.

Threat Vectr will update this story when Microsoft publishes the fixed engine build number.

© 2026 Threat Vectr