Microsoft Defender RoguePlanet Zero-Day
Analysis based on 8 articles · First reported Jun 17, 2026 · Last updated Jun 18, 2026
The disclosure of the RoguePlanet zero-day vulnerability in Microsoft Defender Antivirus is likely to cause concern among users and businesses relying on Microsoft's security products, potentially leading to a decrease in confidence in Microsoft's ability to protect its systems. This could result in a short-term negative impact on Microsoft's stock price and increased demand for alternative cybersecurity solutions. The cybersecurity industry may see increased activity as companies scramble to address potential exploits.
Microsoft has officially acknowledged a critical zero-day vulnerability, codenamed RoguePlanet (CVE-2026-50656), in its Microsoft Defender Antivirus software. This privilege escalation flaw, with a CVSS score of 7.8, affects the Microsoft Malware Protection Engine and can be exploited locally with low privileges and no user interaction. Security researcher Nightmare Eclipse publicly released a proof-of-concept (PoC) exploit on June 10, 2026, just hours after Microsoft's June 2026 Patch Tuesday rollout. The exploit targets a Time-of-Check to Time-of-Use (TOCTOU) race condition and can spawn a Windows command prompt with NT AUTHORITY\SYSTEM privileges. The vulnerability affects fully patched Windows 10 and Windows 11 systems, and its reliability varies due to its race-condition nature. Microsoft is actively developing a security patch, but no release date has been announced. The public disclosure of this and other vulnerabilities by Nightmare Eclipse stems from a dispute with Microsoft over their vulnerability reporting process, with Microsoft criticizing the irresponsible disclosure.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard