A Zero-Day Vulnerability Discovered in Microsoft Defender Exposes Millions to Attackers
In a worrying turn of events, a security researcher known as Nightmare Eclipse has uncovered a critical vulnerability in Microsoft’s Defender software that can allow attackers to gain full control over fully patched Windows 10 and Windows 11 devices. Dubbed “RoguePlanet,” this zero-day exploit takes advantage of a race condition within the security solution, allowing malicious actors to spawn a command prompt with SYSTEM privileges.
The vulnerability, identified as CVE-2026-50656, affects millions of users worldwide who rely on Microsoft Defender for protection against malware and other online threats. Nightmare Eclipse, the researcher behind the discovery, has been vocal about their frustration with Microsoft’s bug bounty and vulnerability disclosure practices, which they claim have led to a series of contentious disputes between the two parties.
According to Nightmare Eclipse, the RoguePlanet exploit is particularly concerning because it can be triggered regardless of whether real-time protection is enabled or not. This means that even users who have taken steps to secure their systems may still be vulnerable to attack. Furthermore, the researcher has reported achieving a 100% success rate with some test machines, indicating that the vulnerability is both potent and reliable.
Microsoft has since confirmed that it was working on a patch for CVE-2026-50656 as far back as June 16, but has yet to publicly acknowledge Nightmare Eclipse’s role in discovering the flaw. However, on Wednesday, the company released an update to the Microsoft Malware Protection Engine (version 1.1.26060.3008) that addresses the vulnerability.
This latest development is just one of several high-profile zero-day exploits uncovered by Nightmare Eclipse over the past few months. The researcher has previously disclosed vulnerabilities affecting Windows components such as BitLocker, and has been vocal about their concerns regarding Microsoft’s handling of bug bounties and vulnerability disclosures.
So what can users do to protect themselves? In this case, the key takeaway is that security teams should be vigilant in testing all layers of their systems before attackers have a chance to exploit them. By doing so, they can reduce the risk of successful attacks and ensure that their networks are better equipped to withstand emerging threats.
In practical terms, users should ensure that their Microsoft Defender software is up-to-date and running with the latest version of the Malware Protection Engine (1.1.26060.3008 or later). Furthermore, security teams should consider conducting regular breach and attack simulation tests to validate their SIEM and EDR rules, thereby reducing the likelihood of successful attacks slipping through undetected.
Ultimately, this latest development serves as a stark reminder that zero-day exploits can be both potent and unpredictable, and that even the most secure systems can be vulnerable to attack if left unpatched. By staying informed and taking proactive steps to protect their networks, users can reduce their exposure to emerging threats and minimize the risk of successful attacks.
Source: Bleeping Computer — 2026-07-09