logo

Microsoft Reins in RoguePlanet Zero-Day Threat

ID: 6b3c73c2-8ec7-53b1-8b5a-44bb64a7fca7

STIX ID: report--6b3c73c2-8ec7-53b1-8b5a-44bb64a7fca7

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-07-09

Date Updated: 2026-07-17

Author: Rob Wright

...
...

Microsoft issued an out-of-band patch for RoguePlanet (CVE-2026-50656), a Windows Defender elevation-of-privilege flaw (CVSS 7.8) for which a public proof-of-concept was published by a researcher known as "Nightmare-Eclipse"; exploitation requires local access but can elevate a standard user to SYSTEM and enable tampering with security tooling and persistence. Microsoft says no confirmed in-the-wild exploitation, while Qualys reports attacks; organizations are advised to apply the Microsoft Malware Protection Engine update, harden endpoint local execution controls, and monitor for privilege-escalation indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.