Description
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
Published: 2026-06-16
Score: 7.8 High
EPSS: 10.7% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft reports an elevation of privilege flaw in its Malware Protection Engine, a core component of Microsoft Defender, that has been publicly referred to and could allow a malicious actor to gain higher privileges within the system. The description does not specify suggesting local presence or an existing foothold.

Affected Systems

The flaw affects the Microsoft Malware Protection Engine, which is the primary part of Microsoft Defender on Windows platforms. No particular version numbers are listed, implying that all current releases of the engine may be impacted until a vendor patch is issued.

Risk and Exploitability

With a CVSS score of 7.8, the vulnerability is rated as high severity, and the EPSS score of 3% indicates a moderate probability of exploitation. The flaw is not listed in the CISA KEV catalog. Because the reported information does not provide a clear attack vector, the likely scenario involves local or pre‑existing system access; remote exploitation is not confirmed.

Generated by OpenCVE AI on July 22, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official security update for the Microsoft Malware Protection Engine once Microsoft releases it.
  • Maintain Microsoft Defender and all related components up to date through Windows Update or Microsoft Endpoint Manager to ensure the vulnerability is fixed.
  • If a patch is not yet available, limit execution of untrusted scripts or code that interact with the Malware Protection Engine and monitor Microsoft advisories for interim mitigations.

Generated by OpenCVE AI on July 22, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Tue, 16 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Description Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
Title Microsoft Defender Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft malware Protection Engine
Weaknesses CWE-59
CPEs cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft malware Protection Engine
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C'}


Subscriptions

Microsoft Malware Protection Engine
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-15T20:10:46.685Z

Reserved: 2026-06-05T14:33:50.831Z

Link: CVE-2026-50656

cve-icon Vulnrichment

Updated: 2026-06-16T18:36:21.914Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-16T19:16:59.683

Modified: 2026-06-16T20:42:25.013

Link: CVE-2026-50656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T16:30:06Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')