
Microsoft released a patch on Wednesday addressing a zero-day vulnerability in its Defender security engine, identified as CVE-2026-50656 and tracked under the name RoguePlanet. The vulnerability, which came to public attention in June when researcher NightmareEclipse disclosed it along with exploit code, allows remote attackers to gain administrative access to Windows 10 and Windows 11 machines even when real-time protection is disabled.
The fix was delivered through an update to the Microsoft Malware Protection Engine, which distributes automatically without user intervention. The patch also included what Microsoft described as defense-in-depth updates to enhance security features. However, NightmareEclipse indicated in a statement on Thursday that the new mitigations introduce a problem affecting mpengine.dll, the driver associated with the protection engine.
According to the researcher, the defense-in-depth additions create a flaw in how the system handles certain file operations and data storage. The issue involves a mechanism in SpyNet, a cloud service that reports suspicious software to Microsoft, combined with a handling exception for Zone. Identifier files—hidden metadata files that Windows associates with externally sourced files. Under normal circumstances, Defender places strict limits on file sizes during scanning and quarantine operations to prevent disk exhaustion.
NightmareEclipse outlined a potential exploitation method using Server Message Block, a network file-sharing protocol. The attack would require a specially configured SMB server to serve malicious files paired with extremely large alternative data stream files while maintaining stalled connections, potentially causing Defender to lock resources and consume entire disk capacity. While such an attack would not crash the system, it could cause widespread application and service failures due to insufficient disk space.
Microsoft confirmed awareness of the report and stated it is investigating the matter. This development marks the latest chapter in an escalating dispute between the company and NightmareEclipse that began in May, involving multiple vulnerability disclosures and public disagreements over responsible disclosure practices.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI