RoguePlanet: privilege escalation in the engine behind Microsoft Defender

Microsoft has published CVE-2026-50656, named RoguePlanet, an elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender. The CVE record scores it 7.8, rated high, and states that Microsoft is preparing a security update. Update details were not yet available at the time of the observation. CISA's ADP enrichment marks exploitation as proof-of-concept and technical impact as total, and the record references public exploit material.

What this means for your organisation

The flaw sits inside the very security product meant to protect your endpoints, and the engine runs with high privileges on practically every Windows machine you operate. An attacker who has already gained a foothold with an ordinary user account can use this to take full control of the machine. The engine normally updates automatically, so the most valuable thing you can do now is verify that this mechanism actually works on every device, including those rarely online.

Berigo recommends

  • Verify that automatic engine updates for Defender are enabled and working across the entire endpoint estate.
  • Report on machines lagging behind on engine version, and follow up the ones that have not checked in.
  • Track Microsoft's update guidance for when the fix is actually published, and verify installation afterwards.
  • Review whether ordinary users hold local administrator rights, which amplifies the impact of this class of flaw.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch