Microsoft Rolls Out Automatic Patch for Critical RoguePlanet Defender Vulnerability

Patch details: The RoguePlanet fix is delivered as Microsoft Malware Protection Engine version 1.1.26060.3008, deployed automatically through engine updates for most users. Users can verify the patch by checking Security Center > Info > Module Version, with versions earlier than 1.1.26060.3008 deemed vulnerable.
Exploit mechanics: RoguePlanet targets a race condition in the Malware Protection Engine (mpengine.dll). An attacker with local access can spawn a command shell running with SYSTEM privileges, and the attack does not require user interaction.
Timeline of disclosure and patching: A proof-of-concept was made public in early June (around June 9–10); Microsoft issued a security advisory on June 16 and updated it on July 8, with the fix delivered via the Malware Protection Engine update in June–July.
Broad impact across Defender ecosystem: The vulnerability affects the Microsoft Malware Protection Engine, a core component powering Defender Antivirus, Microsoft Security Essentials, and System Center Endpoint Protection, meaning the patch reaches a wide range of Defender deployments.
Post-patch observations: Nightmare Eclipse has reported memory-leak issues and quarantined-file handling concerns following the patch, though it remains unclear whether these can be weaponized.
Microsoft has patched a zero-day flaw in Windows Defender that lets a local attacker seize full control of a system. The vulnerability, called RoguePlanet and tracked as CVE-2026-50656, carries a CVSS score of 7.8 and can spawn a command shell running at SYSTEM level — the highest privilege on a Windows machine — without any user interaction, according to Bleeping Computer.
The fix arrives roughly one month after researcher "Nightmare Eclipse" published a working exploit. The patch ships as Microsoft Malware Protection Engine version 1.1.26060.3008 and rolls out automatically for most users, according to Security Affairs.
RoguePlanet lives inside mpengine.dll — the core library of the Microsoft Malware Protection Engine. It exploits a race condition, a bug where two processes compete for the same resource at the same time. An attacker with local access can win that race and force Defender to run attacker-controlled code as SYSTEM, according to Security Week.
No user interaction is needed. An attacker just needs to already be logged into the machine. From there, the exploit opens a command shell with full administrative rights. HEAL Security noted the attack path is straightforward, making the flaw especially dangerous on shared or enterprise systems.
Nightmare Eclipse made a proof-of-concept exploit public around June 9–10. Microsoft issued a formal security advisory on June 16, then updated it on July 8. The engine patch rolled out in stages across June and July, according to Real Hacker News.
The gap between public exploit and patch gave attackers a window to act. Security Week reported that Microsoft began distributing the fix "one month after a researcher published a zero-day exploit." There are currently no confirmed widespread attacks in the wild.
The Malware Protection Engine powers more than just Windows Defender. It also runs Microsoft Security Essentials and System Center Endpoint Protection. That broad footprint means the flaw touches a huge range of both consumer and enterprise machines, according to Security Affairs.
Users can check if they are protected by opening Security Center, going to Info, and checking the Module Version. Any version earlier than 1.1.26060.3008 is still vulnerable. Most users get the update automatically, but HEAL Security warned that delayed or skipped updates leave systems exposed.
Nightmare Eclipse did not stop at the patch. Post-patch analysis flagged two new concerns: memory-leak issues and problems with how Defender handles quarantined files. Bleeping Computer reported these findings, though it remains unclear if either issue can be turned into a working exploit.
Microsoft also included defense-in-depth improvements in the engine update alongside the direct CVE-2026-50656 fix. These are hardening changes designed to make future attacks harder, even if no specific new flaw is named. Security teams should still review systems for full patch confirmation.
Publishers
16
Articles
3
Reach
19