Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
ID: 22235295-86a2-5595-8af7-802300269b73
STIX ID: report--22235295-86a2-5595-8af7-802300269b73
Feed Name: The Hacker News
Microsoft patched a high-severity privilege-escalation flaw in the Microsoft Malware Protection Engine (CVE-2026-50656, "RoguePlanet") that allows an attacker to spawn a SYSTEM shell and execute arbitrary code; the researcher Chaotic Eclipse demonstrated a working exploit that functions on up-to-date Windows systems. The researcher also reported that the new Defender "defense-in-depth" updates can cause an 8-byte data leak via Zone.Identifier Alternate Data Streams and described an SMB-based technique that can lock files and exhaust disk space, producing a denial-of-service scenario; Microsoft said it is investigating and released an updated engine version to remediate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
