Patch for Windows Defender 0-day could allow attackers to fill hard disk

by | Aug 12, 2026 | Technology

Patch for Windows Defender 0-day could allow attackers to fill hard disk

Microsoft released a patch on Wednesday addressing a zero-day vulnerability in its Defender security engine that became publicly known in June. The flaw, tracked as CVE-2026-50656 and named RoguePlanet, allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines even when real-time protection is disabled. The vulnerability was disclosed by NightmareEclipse, an anonymous researcher who also published exploit code.

The company deployed an update to the Microsoft Malware Protection Engine along with what it described as defense-in-depth security improvements. However, on Thursday, NightmareEclipse claimed the newly introduced mitigations introduce a problem in the driver associated with the protection engine that could enable attackers to exhaust available disk space. According to the researcher, a component called SpyNet, which transmits reports about suspicious software to Microsoft, plays a role in the potential mass file-writing behavior.

Normally, Defender enforces limits on file sizes written during scanning and quarantine operations to prevent disk exhaustion. The researcher identified what he characterized as an exception involving Zone. Identifier metadata files, which Windows automatically attaches to externally sourced files. The researcher explained that a malicious actor could exploit this behavior using a custom Server Message Block server to serve a specially crafted file followed by an enormous metadata file, potentially causing Defender to hang and lock up disk space.

The dispute between NightmareEclipse and Microsoft has escalated since May, when the researcher alleged the company silently patched a vulnerability he had privately reported. Subsequently, the researcher disclosed multiple vulnerabilities and exploit code before patches were available. Microsoft publicly criticized the disclosure approach as irresponsible and suggested potential legal action, though later withdrew that threat following public criticism. Microsoft said it is investigating the latest report.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI