PT-2026-49756 · Microsoft · Windows 11+3

CVE-2026-50656

·

Published

2026-06-09

·

Updated

2026-09-11

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Malware Protection Engine (affected versions not specified) Windows 11 25H2 Windows Server 2025 Windows 10 (affected versions not specified)
Description An elevation of privilege flaw, publicly known as RoguePlanet, exists in the Microsoft Malware Protection Engine used by Microsoft Defender. This issue allows a local user to gain administrative control and execute code with NT AUTHORITYSYSTEM privileges. The flaw is rooted in a race condition and synchronization errors when using shared resources, remaining exploitable even if real-time protection is disabled.
A subsequent bypass known as ShieldBreak demonstrates that previous fixes were incomplete. This method exploits the interaction between the Microsoft Defender recovery pipeline, the Cloud Filter API, and the Windows NT Object Manager namespace. It involves registering a fake cloud sync provider and using CF OPERATION TYPE RESTART HYDRATION to replace file content with a malicious DLL while Defender processes the file. To bypass NTFS junction restrictions, it utilizes shadow directories and symbolic links in the Object Manager to redirect the payload to C:WindowsSystem32phoneinfo.dll via a UNC loopback to 127.0.0.1C$. Finally, a fabricated Windows Error Reporting directory and Report.wer file trigger the QueueReporting scheduled task to load the DLL with SYSTEM privileges.
Technical details include the use of the CfRegisterSyncRoot function and the NtCreateSymbolicLinkObject and ConnectNamedPipe Win APIs. The vulnerability affects the MsMpEng.exe process token handling.
Recommendations For Microsoft Malware Protection Engine, apply the security update provided by Microsoft to address the RoguePlanet flaw. For Windows 11 25H2 and Windows Server 2025, at the moment, there is no information about a newer version that contains a fix for the ShieldBreak bypass. For Windows 10, at the moment, there is no information about a newer version that contains a fix for the ShieldBreak bypass. Restrict local administrator rights and enforce the principle of least privilege across all endpoints. Monitor for unusual privilege escalation, Defender tampering, and suspicious child process creation from MsMpEng.exe. Restrict the use of the CfRegisterSyncRoot function by processes that are unsigned or not recognized as cloud software.

Exploit

Fix

LPE

RCE

Race Condition

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08019
CVE-2026-50656

Affected Products

Defender
Msmpeng
Windows 10
Windows 11