Last Updated: 2026-06-17T23:25:13Z
CVSSv3: 7.8
Assigned CVE-2026-50656 on 2026-06-17T07:00:00Z
Nightmare Eclipse does it again.
RoguePlanet
A race condition in Windows Defender resulting in Local Privilege Escalation
Apparently a patch was pushed during development that limited the capability of the exploit:
Now after mid May, a patch was pushed to Defender in mpengine!SysIO* api that made any junction attacks useless. Rewriting RoguePlanet to make it functional again drained my soul and I couldn’t complete the other scenarios and for now it remains unclear if RoguePlanet is limited to LPE or there is some sort of way to turn it into an RCE.
I think the bitlocker bypass might be doable even with the changes but I’m really not sure.
However, they seem to have more in store for us, perhaps waiting for the July 14th date they mentioned in a previous blog post:
Microsoft efforts to protect Defender from path redirection attacks are useless, I have a batch of memory corruption vulnerabilities in defender as well and not to mention the other batch of vulnerabilities I have in several other components.
While they made another GitHub account to post this PoC, it appears they are going to be uploading to a privately hosted Gitea instance at projectnightcrawler moving forward.
Vulnerable claims:
| Windows 11 | Windows 10 | Windows Server |
|---|---|---|
| Official channel + Canary | June 2026 patch | (With PoC tweaking) |
| Update 1.453.20.0 (With slight tweaking) |
Archived PoC Link from GitHub:
Sources:
