Microsoft Confirms RoguePlanet Zero-Day Exploit Targeting Defender
ID: ff46ef51-7d7b-56ff-ba83-13a9627c93ad
STIX ID: report--ff46ef51-7d7b-56ff-ba83-13a9627c93ad
Feed Name: GBHackers
Microsoft confirmed a zero-day vulnerability (CVE-2026-50656) in Microsoft Defender; a public proof-of-concept called “RoguePlanet” demonstrates a reliable local privilege-escalation exploit that leverages improper symbolic link handling (CWE-59). The flaw carries a CVSS v3.1 score of 7.8, is marked as functionally exploitable, and the researcher claims it can work regardless of real-time protection being enabled, raising high-risk concerns though Microsoft has not confirmed active exploitation. Security teams are advised to monitor for suspicious filesystem link activity and tune EDR to detect unauthorized link resolution and file access involving Defender components while awaiting a patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
