PT-2026-49756 · Microsoft · Msmpeng+3
CVE-2026-50656
·
Published
2026-06-09
·
Updated
2026-07-15
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Defender versions prior to engine version 1.1.26060.3008
Description
An elevation of privilege flaw, publicly known as RoguePlanet, exists in the Microsoft Malware Protection Engine (
mpengine.dll), which provides core scanning and detection capabilities for Microsoft Defender. The issue is caused by a TOCTOU (Time-of-Check to Time-of-Use) race condition, where synchronization errors occur when using a shared resource. A local attacker can exploit this flaw to elevate their privileges from a standard user account to the highest level of authority on Windows, known as NT AUTHORITYSYSTEM, potentially gaining complete control of the affected system. This exploit can function regardless of whether real-time protection is enabled.Recommendations
Update the Microsoft Malware Protection Engine to version 1.1.26060.3008 or higher.
Review endpoints for unusual privilege escalation, Defender tampering, and suspicious process activity.
Enforce least privilege and remove unnecessary local admin rights.
Strengthen EDR/MDR monitoring and centralize logs for faster detection.
Validate endpoint baselines, security policies, and tamper protection settings.
Exploit
Fix
LPE
RCE
Link Following
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Defender
Msmpeng
Windows 10
Windows 11