Patch for Windows Defender 0-day could allow attackers to fill hard disk

by | Jul 29, 2026 | Technology

Patch for Windows Defender 0-day could allow attackers to fill hard disk

Microsoft released a security update on Wednesday addressing a zero-day vulnerability in its Defender antivirus engine. The flaw, designated CVE-2026-50656 and known as RoguePlanet, was publicly disclosed in June by a researcher operating under the pseudonym NightmareEclipse. The vulnerability permits remote attackers to obtain administrative access on Windows 10 and Windows 11 systems, even when real-time protection has been turned off.

The patch was delivered through an update to the Microsoft Malware Protection Engine alongside additional defense-in-depth security improvements. According to NightmareEclipse’s analysis posted on July 13, however, these new mitigations may introduce a separate problem. The researcher indicated that modifications to mpengine.dll and SpyNet, Microsoft’s cloud-based reporting service, could potentially allow attackers to fill a hard drive by writing excessive amounts of data. Specifically, the vulnerability appears to involve the handling of Zone. Identifier files, which are metadata streams that Windows automatically attaches to files from external sources like downloads or email.

NightmareEclipse explained that the exploit would require a specially configured Server Message Block server to trigger the problematic behavior. By serving a malicious file alongside an oversized Zone. Identifier metadata stream and then failing to respond to read requests while maintaining the connection, an attacker could cause Defender to exhaust all available disk space. While such a scenario would not crash the machine outright, the researcher noted that a full disk typically causes applications and services to fail unpredictably.

The disclosure continues an ongoing dispute between NightmareEclipse and Microsoft dating to May. The researcher has released details and exploit code for multiple vulnerabilities before Microsoft could issue patches, citing what was characterized as Microsoft’s silent patching of a previously reported flaw. Microsoft responded by criticizing the disclosure approach and initially suggested potential legal consequences, though later withdrew that position following public criticism. Microsoft confirmed awareness of the latest report and stated it is investigating the matter.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI