PT-2026-49756 · Microsoft · Windows 11+3
CVE-2026-50656
·
Published
2026-06-09
·
Updated
2026-09-11
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Malware Protection Engine (affected versions not specified)
Windows 11 25H2
Windows Server 2025
Windows 10 (affected versions not specified)
Description
An elevation of privilege flaw, publicly known as RoguePlanet, exists in the Microsoft Malware Protection Engine used by Microsoft Defender. This issue allows a local user to gain administrative control and execute code with
NT AUTHORITYSYSTEM privileges. The flaw is rooted in a race condition and synchronization errors when using shared resources, remaining exploitable even if real-time protection is disabled.A subsequent bypass known as ShieldBreak demonstrates that previous fixes were incomplete. This method exploits the interaction between the Microsoft Defender recovery pipeline, the Cloud Filter API, and the Windows NT Object Manager namespace. It involves registering a fake cloud sync provider and using
CF OPERATION TYPE RESTART HYDRATION to replace file content with a malicious DLL while Defender processes the file. To bypass NTFS junction restrictions, it utilizes shadow directories and symbolic links in the Object Manager to redirect the payload to C:WindowsSystem32phoneinfo.dll via a UNC loopback to 127.0.0.1C$. Finally, a fabricated Windows Error Reporting directory and Report.wer file trigger the QueueReporting scheduled task to load the DLL with SYSTEM privileges.Technical details include the use of the
CfRegisterSyncRoot function and the NtCreateSymbolicLinkObject and ConnectNamedPipe Win APIs. The vulnerability affects the MsMpEng.exe process token handling.Recommendations
For Microsoft Malware Protection Engine, apply the security update provided by Microsoft to address the RoguePlanet flaw.
For Windows 11 25H2 and Windows Server 2025, at the moment, there is no information about a newer version that contains a fix for the ShieldBreak bypass.
For Windows 10, at the moment, there is no information about a newer version that contains a fix for the ShieldBreak bypass.
Restrict local administrator rights and enforce the principle of least privilege across all endpoints.
Monitor for unusual privilege escalation, Defender tampering, and suspicious child process creation from
MsMpEng.exe.
Restrict the use of the CfRegisterSyncRoot function by processes that are unsigned or not recognized as cloud software.Exploit
Fix
LPE
RCE
Race Condition
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Defender
Msmpeng
Windows 10
Windows 11