RoguePlanet zero-day in Windows Defender grants SYSTEM control on fully patched PCs
Security researchers disclosed RoguePlanet, a zero-day in Windows Defender that abuses the tool's own quarantine process to win a race condition and gain SYSTEM level access on fully updated Windows 10 and 11 machines. Microsoft $MSFT confirmed the flaw, tracked as CVE-2026-50656
A newly disclosed zero-day called RoguePlanet turns Windows Defender against the machine it protects. Researchers say the exploit chains NTFS junctions, opportunistic locks, and the Volume Shadow Copy service to abuse Defender's quarantine and remediation workflow, producing a command prompt that runs as SYSTEM, the highest level of access on Windows. It reportedly works on devices that already installed the June 2026 updates, whether or not real time protection is enabled. Because it still needs an initial foothold, it is an escalation tool rather than a remote break-in. Microsoft $MSFT confirmed the flaw as CVE-2026-50656 and says a high quality security update is in development, without giving a date. Until then, security teams are watching for unusual Defender activity. Sources: BleepingComputer, The Hacker News, Help Net Security, SecurityWeek, Morphisec.