CVE-2026-50656

HIGH

Microsoft Defender Elevation of Privilege Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-50656. PoCs published by g0thamRabb1t, HORKimhab, 0xBlackash.

AI-analyzed exploit summary The repository contains only PNG image files with no actual exploit code, technical details, or proof-of-concept for CVE-2026-50656. The README and code files are absent, and the images appear to be screenshots or diagrams without functional exploit content.

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Exploits (3)

nomisec SUSPICIOUS 1 stars
by g0thamRabb1t · poc
https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation

The repository contains only PNG image files with no actual exploit code, technical details, or proof-of-concept for CVE-2026-50656. The README and code files are absent, and the images appear to be screenshots or diagrams without functional exploit content.

Classification
Suspicious 95%
Attack Type
Other
Complexity
Unknown
Reliability
Unknown
Target: unknown
No auth needed
mistral-large-3 · analyzed Jul 10, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/50xxx/CVE-2026-50656.md

The repository contains no actual exploit code or technical details about CVE-2026-50656. Instead, it links to external GitHub repositories and encrypted backup files, which is a common tactic in social engineering lures.

Classification
Suspicious 98%
Attack Type
Other
Complexity
Unknown
Reliability
Unknown
Target: Microsoft Defender (Microsoft Malware Protection Engine)
No auth needed
mistral-large-3 · analyzed Jul 10, 2026 Full analysis →
github SCANNER
by 0xBlackash · c++poc
https://github.com/0xBlackash/CVE-2026-50656

The repository contains a C++ tool that checks for the presence of CVE-2026-50656, a TOCTOU vulnerability in Microsoft Defender's MsMpEng engine, by simulating race conditions with symbolic links. It does not exploit the vulnerability but detects potential susceptibility.

Classification
Scanner 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Microsoft Malware Protection Engine (MsMpEng.exe)
No auth needed
Prerequisites: Microsoft Defender running with Real-Time Protection enabled · Ability to create symbolic links
mistral-large-3 · analyzed Jun 18, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory patch
Microsoft Defender Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656

Scores

CVSS v3 7.8
EPSS 0.1075
EPSS Percentile 95.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (3)
microsoft/malware_protection_engine
Microsoft/Microsoft Malware Protection Engine -
Microsoft/Microsoft Malware Protection Engine 1.1.0.0 - 1.1.26060.3008
Published Jun 16, 2026
Tracked Since Jun 17, 2026