Junglewise Threat Intelligence

CVE-2026-50656: Microsoft Defender Malware Protection Engine privilege escalation

CVE-2026-50656 · Severity: high · CVSS 7.8 · Published 2026-06-16

Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Defender, the built-in antivirus and security software for Windows. This flaw, known as 'RoguePlanet', could allow an attacker who already has limited access to a computer to gain full administrative control. This would enable them to bypass security protections, access sensitive files, or install malicious software.

Technical details

An elevation of privilege vulnerability exists in the Microsoft Malware Protection Engine (mpengine.dll) within Microsoft Defender. The flaw is categorized as CWE-59 (Improper Link Resolution Before File Access), suggesting a symlink or hard link following issue where the engine performs file operations on a path controlled by a low-privileged user. An attacker with local access and low privileges can exploit this to perform actions with the higher privileges of the Malware Protection Engine, typically SYSTEM. Microsoft has acknowledged the issue and is working on a security update.

Affected products

  • Microsoft Defender Malware Protection Engine

Timeline

  • 2026-06-16: disclosed: Initial disclosure by Microsoft and NVD publication.

References