PT-2026-49756 · Microsoft · Msmpeng+3

CVE-2026-50656

·

Published

2026-06-09

·

Updated

2026-07-15

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Defender versions prior to engine version 1.1.26060.3008
Description An elevation of privilege flaw, publicly known as RoguePlanet, exists in the Microsoft Malware Protection Engine (mpengine.dll), which provides core scanning and detection capabilities for Microsoft Defender. The issue is caused by a TOCTOU (Time-of-Check to Time-of-Use) race condition, where synchronization errors occur when using a shared resource. A local attacker can exploit this flaw to elevate their privileges from a standard user account to the highest level of authority on Windows, known as NT AUTHORITYSYSTEM, potentially gaining complete control of the affected system. This exploit can function regardless of whether real-time protection is enabled.
Recommendations Update the Microsoft Malware Protection Engine to version 1.1.26060.3008 or higher. Review endpoints for unusual privilege escalation, Defender tampering, and suspicious process activity. Enforce least privilege and remove unnecessary local admin rights. Strengthen EDR/MDR monitoring and centralize logs for faster detection. Validate endpoint baselines, security policies, and tamper protection settings.

Exploit

Fix

LPE

RCE

Link Following

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08019
CVE-2026-50656

Affected Products

Defender
Msmpeng
Windows 10
Windows 11