
Microsoft released a patch on Wednesday addressing a zero-day vulnerability in its Defender security engine known as RoguePlanet, tracked as CVE-2026-50656. The flaw was initially disclosed in June by a researcher using the pseudonym NightmareEclipse and allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines even when real-time protection has been disabled. The patch was distributed through an automatic update to the Microsoft Malware Protection Engine used by the Defender antivirus application.
However, on Thursday, NightmareEclipse reported that the defensive measures included in the patch may create unintended consequences. The researcher indicated that newly introduced mitigations produce problematic behavior in mpengine.dll, the driver associated with the Microsoft Malware Protection Engine, along with changes to SpyNet, a cloud service for reporting suspicious software. These elements combine to potentially allow attackers to exhaust all available hard drive space by writing massive amounts of data.
According to the researcher, the vulnerability stems from an exception to Defender’s normal limits on file size during scanning and quarantining operations. Specifically, functions within mpengine.dll related to SpyNet attempt to maintain local copies of Zone. Identifier alternative data streams without enforcing size restrictions. A Zone. Identifier is a hidden metadata file Windows associates with externally sourced files to track their origin and security classification.
NightmareEclipse detailed a potential exploitation method using Server Message Block, a network file-sharing protocol. The attack would require a specially configured SMB server to serve a malicious file followed by a massive alternative data stream, eventually becoming unresponsive to read requests while maintaining the connection. This scenario could cause Defender to hang while retaining file locks that consume all available disk space, degrading system performance and causing application failures without necessarily crashing the machine.
Microsoft stated that it is aware of the report and investigating the matter. The incident reflects ongoing tensions between the company and the researcher, which have escalated since May when NightmareEclipse publicly disclosed vulnerability details and exploit code ahead of available patches, citing Microsoft’s handling of a previously reported vulnerability.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI