Drooid Logo
Back to story perspectives

Full Breakdown

Microsoft Patches “RoguePlanet” Defender Zero-Day After Public Disclosure

7/10/2026, 6:23:55 PM

Core Event

Microsoft released an update to the Microsoft Malware Protection Engine (version 1.1.26060.3008) that resolves CVE-2026-50656, a privilege-escalation flaw in mpengine.dll. The vulnerability, rated 7.8 on the CVSS scale, allows a race-condition exploit to spawn a SYSTEM-level command shell, giving an attacker full control of the host. The fix was issued in early July 2026, separate from the regular Patch Tuesday bundle, and applies to Windows 10 and Windows 11 systems that already carry the June 2026 updates.

Background & Researcher Dispute

Security researcher Chaotic Eclipse (also known as Nightmare Eclipse) first disclosed “RoguePlanet” in June 2026, publishing technical details and proof-of-concept code that reportedly worked even when real-time protection was disabled. The researcher, who claims former employment at Microsoft, has previously disclosed three other Defender flaws—BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498) and RedSun (CVE-2026-41091). Since April 2026, Nightmare Eclipse has accused Microsoft of ignoring reports, deleting submission accounts and treating independent researchers contemptuously, fueling a public dispute that intensified after Microsoft warned that publishing exploit code could have legal consequences.

Official Statements & Responses

Microsoft emphasized that the update requires no manual action, noting that its antimalware software automatically checks for engine and definition updates multiple times daily. The company reiterated that default configurations keep the Malware Protection Engine current for both enterprise deployments and end users.

Criticism & Opposition

Nightmare Eclipse contended that the exploit’s success varies, describing it as “hit or miss” and claiming a 100 percent success rate on some machines while it “struggled to work on others.” The researcher also alleged that Microsoft removed public repositories hosting the proof-of-concept before relocating the code to a self-hosted site, and that the firm has not clarified whether the bug was ever exploited in the wild.

Verbatim Quotes

  • “For enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically,” — Microsoft
  • “Depending on which Microsoft antimalware software is used and how it is configured, the software may search for engine and definition updates every day when connected to the Internet, up to multiple times daily. Customers can also choose to manually check for updates at any time.” — Microsoft
  • “The exploit is a race condition, so it's a hit or miss,” — Nightmare Eclipse, researcher
  • “I have managed to get a 100 percent success rate on some machines while it struggled to work on others.” — Nightmare Eclipse, researcher