logo

Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch

ID: 581a3284-1e20-5b7c-a364-6809f5d93d8e

STIX ID: report--581a3284-1e20-5b7c-a364-6809f5d93d8e

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Guru Baran

...
...

Microsoft acknowledged a critical zero-day (CVE-2026-50656, “RoguePlanet”) in the Microsoft Malware Protection Engine used by Defender that enables a TOCTOU race-condition elevation of privilege to NT AUTHORITY\SYSTEM on fully patched Windows 10 and 11; a public, functional proof-of-concept was released, works regardless of real-time protection state, and Microsoft is working on a patch while rating exploitation as "More Likely."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.