CTIPilot

Microsoft Security Essentials

product · product:microsoft-security-essentials

Coverage timeline
1
first 2026-07-09 → last 2026-07-09
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
6
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

Releases covered
Microsoft Security Essentials
ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed · ATT&CK page ↗

Story timeline

  1. 2026-07-09CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series
    trending-vulnerabilitiesMicrosoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • msrc.microsoft.com1 (50%)
  • security-hub.ncsc.admin.ch1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Microsoft Security Essentials (1)

2026-07-09 · view entry permalink →

CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series

NCSC-CH's running tracker on the "Nightmare Eclipse" (aka Chaotic Eclipse) researcher's 2026 zero-day PoC series was updated on 2026-07-09 to record that a CVE has been assigned to RoguePlanet: CVE-2026-50656, a local privilege-escalation vulnerability (CWE-59, improper link resolution before file access / "link following") in the Microsoft Malware Protection Engine that underpins Microsoft Defender, System Center Endpoint Protection and Microsoft Security Essentials (NCSC-CH, 2026-07-09). The researcher first disclosed RoguePlanet as an unpatched zero-day on 2026-06-10, describing a race condition in Defender that lets a local attacker "execute arbitrary code or spawn a command shell with SYSTEM-level privileges" (T1068), at which point NCSC-CH logged its status as "Proof of Concept Available, no patch available" (NCSC-CH, 2026-07-09). Microsoft's own record shows the CVE was published 2026-06-16 (CVSS 3.1 7.8, AV:L/AC:L/PR:L/UI:N, rated "Exploitation More Likely", exploitation status "No") and remained without a fix for over three weeks; a revision dated 2026-07-08 confirms Microsoft has now shipped an engine update that closes it, last vulnerable Malware Protection Engine build 1.1.26050.11, first fixed build 1.1.26060.3008 (Microsoft MSRC, 2026-07-08).

Because the Malware Protection Engine (mpengine.dll) auto-updates multiple times a day by default, most estates will already carry the fixed build; Microsoft's guidance is that no manual action is normally required. The operational nuance for this constituency is the exception set: any environment where engine updates are pinned, WSUS-gated, air-gapped, or centrally deferred (System Center Endpoint Protection deployments, offline or OT-adjacent Windows hosts) should explicitly verify the installed engine version rather than assume auto-remediation occurred (Microsoft MSRC, 2026-07-08). Microsoft also notes that hosts with Defender disabled are not in an exploitable state even though vulnerability scanners flag the on-disk binaries. Triage: the exploit abuses a symlink/junction race against files Defender is actively scanning, so the telemetry class is symlink/junction creation targeting Defender scan paths and, on success, MsMpEng.exe (the engine's scan host) spawning an unexpected child process with a SYSTEM token outside the normal signature/engine-update cadence; the update-cadence anchoring is the discriminator from routine engine activity. This closes RoguePlanet specifically; NCSC-CH continues to track the wider Nightmare Eclipse PoC series as a home-region authority, which is the reason a single-host LPE closure like this one is worth surfacing to this constituency at all.

Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656.

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Microsoft Security Response Center 2026-07-08
vulnerability09 Jul 20:38Zmulti-sourceOpen finding ↗