Patch for Windows Defender 0-day could allow attackers to fill hard disk

by | Aug 9, 2026 | Technology

Patch for Windows Defender 0-day could allow attackers to fill hard disk

Microsoft released a patch on Wednesday addressing a zero-day vulnerability in its Defender security engine known as RoguePlanet, tracked as CVE-2026-50656. The flaw, initially disclosed in June by a pseudonymous researcher using the name NightmareEclipse, enables remote attackers to gain administrative access to Windows 10 and Windows 11 machines regardless of whether real-time protection is disabled. The update, delivered through the Microsoft Malware Protection Engine used by the Defender antivirus application, deploys automatically without user intervention.

However, NightmareEclipse contended in a post on Thursday that the patch’s defense-in-depth enhancements introduce a new security problem. The researcher stated that the modifications could enable attackers to exhaust available hard drive space by writing substantial volumes of data to disk. According to the analysis, the issue stems from functionality in mpengine.dll and SpyNet, a cloud service that transmits reports regarding suspicious software to Microsoft. The researcher indicated that Defender typically enforces size restrictions on files written during scanning and quarantine operations.

The potential attack vector involves exploiting an exception in how the Defender engine handles Zone. Identifier files, hidden metadata files that Windows associates with downloaded or externally sourced content. NightmareEclipse explained that a malicious actor could leverage Server Message Block, a file-sharing protocol used on Windows networks, to trigger the problematic behavior by serving specially crafted files that would cause Defender to retain locks on disk space. While such an attack would not crash the system, it would degrade performance and cause application instability.

The disclosure reflects an ongoing dispute between NightmareEclipse and Microsoft that began earlier this year. Microsoft said it is aware of the report and investigating. The conflict intensified in recent months when the researcher released multiple vulnerability details and exploit code prior to Microsoft deploying patches, prompting the company to publicly criticize the disclosure practices and initially suggest potential legal consequences—a position Microsoft later abandoned following public criticism.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI