Summary

A zero-day privilege escalation vulnerability tracked as CVE-2026-50656, dubbed “RoguePlanet,” has been confirmed in the Microsoft Defender Malware Protection Engine. The race condition flaw allows attackers to escalate privileges to SYSTEM on all Windows 10 and Windows 11 systems — and as of June 25, 2026, no patch is available.

Disclosed by security researcher “Chaotic Eclipse,” the vulnerability comes with publicly available functional exploit code. Researchers have reported a 100% success rate on some target machines, and critically, the exploit works even when Microsoft Defender’s real-time protection is enabled. The flaw carries a CVSS 3.1 score of 7.8 and is rated “Important” by Microsoft.

Microsoft has acknowledged the vulnerability and says it is working on a fix, but has not provided a timeline. Disabling Microsoft Defender does not mitigate the issue. Organizations are advised to layer additional prevention controls to block post-escalation activity until the official patch drops.

Source

Commentary

The irony of your antivirus being the privilege escalation vector is peak 2026 security. Defender runs on virtually every Windows machine on the planet, is always-on, and operates with SYSTEM privileges by design — making it the ideal target for exactly this kind of attack. The fact that disabling Defender doesn’t even help underscores how deeply the engine is embedded in the OS.

With public exploit code and no patch in sight, this is a live fire situation. Red teams will fold this into their toolkits immediately if they haven’t already. Blue teams should prioritize post-exploitation detection — monitoring for unusual SYSTEM-context activity originating from the Defender engine process — until Microsoft delivers the fix.

By Allan