CVE-2026-50656 PoC: Microsoft Defender RoguePlanet elevation-of-privilege patch bypass
github.com | vulnerability | High | CVE-2026-50656 | #zero-day | #public-poc | #privilege-escalation | #windows-security | #windows | #defender | #patch-bypass | #cwe-59 | #poc | #microsoft-defender | #cve-2026-50656
Summary
ShieldBreak, a public PoC for CVE-2026-50656, claims a full bypass of Microsoft's RoguePlanet patch—an elevation-of-privilege flaw in the Malware Protection Engine—on Windows 11 25H2 and Server 2025.
Why it matters
The repository publishes a patch-bypass implementation for a Defender elevation-of-privilege flaw, increasing practical risk to affected endpoints. Administrators should update the Malware Protection Engine to a fixed version and validate the PoC only in an explicitly authorized isolated environment; public availability does not by itself confirm exploitation in the wild.
- Vendor
- Microsoft
- Product
- Microsoft Malware Protection Engine / Microsoft Defender
- Affected versions
- Microsoft Malware Protection Engine versions before 1.1.26060.3008; repository reports Windows 11 25H2 Canary and Windows Server 2025 testing, with Windows 10 vulnerable but unsupported by this PoC
- CVSS
- 7.8
- Published
- Collected
Skip to content