Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch
ID: 581a3284-1e20-5b7c-a364-6809f5d93d8e
STIX ID: report--581a3284-1e20-5b7c-a364-6809f5d93d8e
Feed Name: cybersecurityNews.com
Threat Score
Microsoft acknowledged a critical zero-day (CVE-2026-50656, “RoguePlanet”) in the Microsoft Malware Protection Engine used by Defender that enables a TOCTOU race-condition elevation of privilege to NT AUTHORITY\SYSTEM on fully patched Windows 10 and 11; a public, functional proof-of-concept was released, works regardless of real-time protection state, and Microsoft is working on a patch while rating exploitation as "More Likely."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
