blackhatnews.tokyo • 16h
Microsoft Defender: Critical Patch Bypass for CVE-2026-50656 RoguePlanet
A high-severity zero-day vulnerability, designated CVE-2026-50656 (RoguePlanet), has been identified in the Microsoft Defender Malware Protection Engine (mpengine.dll). The flaw stems from a race condition combined with improper link resolution, enabling local attackers to escalate privileges from a low-privileged user to NT AUTHORITY\SYSTEM. While Microsoft released an initial remediation in Engine version 1.1.26060.3008, researcher Chaotic Eclipse has demonstrated a successful patch bypass via the "ShieldBreak" exploit chain. With a public Proof-of-Concept (PoC) now available, the vulnerability poses an immediate risk of local privilege escalation (LPE) across affected Windows environments.
Links:blackhatnews.tokyo, Malware News, Cybersecurity News, Security Affairs, feeds.feedburner.com, helpnetsecurity.com, bleepingcomputer.com, Redsecuretech, Cypro, Kudelskisecurity, Daily, Facebook, Beeble, Nvd, Thrivenextgen, Arcticwolf, Forbes, Crowdstrike, Reddit, Darkreading, Labs, Dataconomy, Csoonline, Itnews, SecurityWeek •