
A security update released by Microsoft on Wednesday to address CVE-2026-50656, a zero-day vulnerability in its Defender security engine, may introduce a new problem that could allow attackers to exhaust hard drive storage, according to NightmareEclipse, the researcher who initially disclosed the flaw.
The vulnerability, tracked as RoguePlanet, came to light in June when NightmareEclipse published details and exploit code. It allows remote attackers to gain administrative access to Windows 10 and Windows 11 systems even when real-time protection is disabled. Microsoft’s patch included updates to the Microsoft Malware Protection Engine alongside what the company described as defense-in-depth security improvements.
In a post on Thursday, NightmareEclipse alleged that the newly introduced mitigations create a flaw in mpengine.dll, the driver for the Malware Protection Engine, that can cause data leakage when opening files. The researcher also identified a potential issue with SpyNet, Microsoft’s cloud service for reporting suspicious software, which may allow attackers to trigger mass file-writing behavior. According to the analysis, Windows Defender normally restricts file sizes during scanning and quarantine operations, but an exception exists for Zone. Identifier files—hidden metadata that Windows associates with externally sourced files. The researcher suggested that malicious actors could exploit this through Server Message Block protocol by setting up a custom server that serves oversized Zone. Identifier files, potentially causing the system to hang and fill the disk while Defender maintains locks on the offending files.
The dispute between NightmareEclipse and Microsoft extends back several months. The researcher has disclosed multiple zero-days, and Microsoft has publicly criticized the disclosure practices while previously indicating potential legal action—a threat the company later withdrew following public backlash. Microsoft said on Thursday that it is investigating the latest report.
Originally reported by Ars Technica. Read the full story →