---
schema: 1
kind: vulnerability
title: "CVE-2026-50656 — Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series"
headline: "Microsoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June"
summary: >
  NCSC-CH's Nightmare Eclipse tracker was updated on 2026-07-09 to record that a
  CVE has been assigned to RoguePlanet (CVE-2026-50656), a link-following (CWE-59)
  local privilege escalation in the Microsoft Malware Protection Engine behind
  Defender that lets a local attacker reach SYSTEM; Microsoft's MSRC record shows
  the engine fix has now shipped. A public PoC existed from 2026-06-10 and the CVE
  sat in "no fix" for over three weeks. The engine auto-updates, so most estates
  are already current — but WSUS-gated, offline or OT-adjacent estates should
  explicitly verify the installed engine build.
discovered_at: "2026-07-09T20:38:00Z"
event_date: "2026-07-08"
run_id: 2026-07-09T2009Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, lpe, priv-esc, poc-public, patch-available]
regions: [switzerland, global]
sectors: [public-sector, energy, water, transport, healthcare, finance, telco]
entities: [actor:nightmare-eclipse, trend:nightmare-eclipse-rogueplanet-defender-toctou-lpe-2026-06, campaign:nightmare-eclipse-microsoft-dcu-threat-greenplasma-miniplasmaaac]
techniques: [T1068]
affected_products: ["Microsoft Defender", "Microsoft System Center Endpoint Protection", "Microsoft Security Essentials"]
cves:
  - id: CVE-2026-50656
    cvss: "7.8"
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status: [poc-public, patch-available]
    affected: "Microsoft Malware Protection Engine ≤ 1.1.26050.11"
    fixed: "1.1.26060.3008"
sources:
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12622"
    publisher: "NCSC-CH / GovCERT.ch Cyber Security Hub"
    date: "2026-07-09"
    role: primary
  - url: "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656"
    publisher: "Microsoft Security Response Center"
    date: "2026-07-08"
    role: primary
closed_sources: []
evidence:
  - quote: "Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656."
    publisher: "Microsoft Security Response Center"
  - quote: "Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally."
    publisher: "Microsoft Security Response Center"
verification: multi-source
sourcing_note: null
confidence: medium
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "On WSUS-gated, air-gapped, offline or OT-adjacent Windows estates where Defender engine updates are deferred or pinned, verify the installed Malware Protection Engine build is ≥ 1.1.26060.3008 (e.g. via Get-MpComputerStatus AMEngineVersion) rather than assuming auto-update reached it."
  - "Continue tracking the Nightmare Eclipse zero-day series via NCSC-CH's running advisory: RoguePlanet is now fixed, but the same researcher's series has previously dropped further unpatched Defender/Windows PoCs, so treat NCSC-CH's tracker as the authority for the current fix status of each."
migrated_from: null
---

NCSC-CH's running tracker on the "Nightmare Eclipse" (aka Chaotic Eclipse) researcher's 2026 zero-day PoC series was updated on 2026-07-09 to record that a CVE has been assigned to **RoguePlanet**: **CVE-2026-50656**, a local privilege-escalation vulnerability (CWE-59, improper link resolution before file access / "link following") in the Microsoft Malware Protection Engine that underpins Microsoft Defender, System Center Endpoint Protection and Microsoft Security Essentials ([NCSC-CH, 2026-07-09](https://security-hub.ncsc.admin.ch/#/posts/12622)). The researcher first disclosed RoguePlanet as an unpatched zero-day on 2026-06-10, describing a race condition in Defender that lets a local attacker "execute arbitrary code or spawn a command shell with SYSTEM-level privileges" (`T1068`), at which point NCSC-CH logged its status as "Proof of Concept Available, no patch available" ([NCSC-CH, 2026-07-09](https://security-hub.ncsc.admin.ch/#/posts/12622)). Microsoft's own record shows the CVE was published 2026-06-16 (CVSS 3.1 7.8, `AV:L/AC:L/PR:L/UI:N`, rated "Exploitation More Likely", exploitation status "No") and remained without a fix for over three weeks; a revision dated 2026-07-08 confirms Microsoft has now shipped an engine update that closes it — last vulnerable Malware Protection Engine build **1.1.26050.11**, first fixed build **1.1.26060.3008** ([Microsoft MSRC, 2026-07-08](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656)).

Because the Malware Protection Engine (`mpengine.dll`) auto-updates multiple times a day by default, most estates will already carry the fixed build — Microsoft's guidance is that no manual action is normally required. The operational nuance for this constituency is the exception set: any environment where engine updates are pinned, WSUS-gated, air-gapped, or centrally deferred (System Center Endpoint Protection deployments, offline or OT-adjacent Windows hosts) should explicitly verify the installed engine version rather than assume auto-remediation occurred ([Microsoft MSRC, 2026-07-08](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656)). Microsoft also notes that hosts with Defender disabled are not in an exploitable state even though vulnerability scanners flag the on-disk binaries. **Triage:** the exploit abuses a symlink/junction race against files Defender is actively scanning, so the telemetry class is symlink/junction creation targeting Defender scan paths and, on success, `MsMpEng.exe` (the engine's scan host) spawning an unexpected child process with a SYSTEM token outside the normal signature/engine-update cadence — the update-cadence anchoring is the discriminator from routine engine activity. This closes RoguePlanet specifically; NCSC-CH continues to track the wider Nightmare Eclipse PoC series as a home-region authority, which is the reason a single-host LPE closure like this one is worth surfacing to this constituency at all.
