Microsoft Defender Patch Bypass: High Severity Zero-Day Privilege Escalation (CVE-2026-50656/RoguePlanet, ShieldBreak)
ID: 517c3ee8-4fe5-508d-b5a2-040ae1e82363
STIX ID: report--517c3ee8-4fe5-508d-b5a2-040ae1e82363
Feed Name: Arctic Wolf
A critical zero-day (CVE-2026-50656, "RoguePlanet") in Microsoft Defender's mpengine.dll enables local privilege escalation to SYSTEM via a race condition and improper link resolution; although Microsoft released a patch, a public bypass named "ShieldBreak" has restored SYSTEM-level exploitation, leaving patched environments at risk across Windows 10, 11 and Windows Server 2025. The report describes the attacker ("Chaotic Eclipse"), the local-only nature of the exploit, detection and mitigation guidance (inventory, blocking vulnerable binaries, ASR rules, tamper protection, and incident playbooks), and emphasizes that current workarounds are temporary until an official fix for the bypass is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
