- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,258
Microsoft: “We are studying the problem” It's been a week... Microsoft: “Okay, we will admit it.”

Microsoft is preparing a fix for a new vulnerability in the Defender, because of which the attacker can get almost complete control in the system. The problem was named RoguePlanet and is tracked as CVE-2026-50656 (CVSS:3.1/AV/L/L/L/L:L/UI::L/H/H:H/H:H/H:H/H:H:H–7.8 High). The error is associated with increased privileges in Microsoft Malware Protection Engine.
Microsoft has confirmed that it is aware of a publicly disclosed vulnerability and is working to release a quality security update. When the correction comes out, the company has not yet announced.
RoguePlanet became known almost a week ago. She was reported by a security specialist Chaotic Eclipse (Nightmare-Eclipse). According to him, the vulnerability is associated with the state of the race and allows you to get a team shell with the rights of SYSTEM. This level of access actually gives the attacker the opportunity to act on behalf of the operating system itself.
The author of the find clarified that the exploit is unstable and depends on the specific machine. On some systems, he managed to achieve 100% successful launches, others the attack was noticeably worse. Later, Nightmare-Eclipse added that the vulnerability works regardless of whether protection is enabled in real time. According to him, RoguePlanet can work in the passive mode of the Defender, although he did not conduct such a check separately.

Microsoft is preparing a fix for a new vulnerability in the Defender, because of which the attacker can get almost complete control in the system. The problem was named RoguePlanet and is tracked as CVE-2026-50656 (CVSS:3.1/AV/L/L/L/L:L/UI::L/H/H:H/H:H/H:H/H:H:H–7.8 High). The error is associated with increased privileges in Microsoft Malware Protection Engine.
Microsoft has confirmed that it is aware of a publicly disclosed vulnerability and is working to release a quality security update. When the correction comes out, the company has not yet announced.
RoguePlanet became known almost a week ago. She was reported by a security specialist Chaotic Eclipse (Nightmare-Eclipse). According to him, the vulnerability is associated with the state of the race and allows you to get a team shell with the rights of SYSTEM. This level of access actually gives the attacker the opportunity to act on behalf of the operating system itself.
The author of the find clarified that the exploit is unstable and depends on the specific machine. On some systems, he managed to achieve 100% successful launches, others the attack was noticeably worse. Later, Nightmare-Eclipse added that the vulnerability works regardless of whether protection is enabled in real time. According to him, RoguePlanet can work in the passive mode of the Defender, although he did not conduct such a check separately.