RoguePlanet is a local privilege-escalation vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender. It involves a race condition and improper link resolution before file access in Defender's remediation processing. A standard, low-privilege local user can exploit the flaw to obtain NT AUTHORITY\SYSTEM privileges. Disclosed in June 2026, the vulnerability was initially addressed by an engine update in July 2026. ShieldBreak, separately tracked as CVE-2026-69414, subsequently bypassed that fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
ShieldBreak is a standalone Visual Studio C++20 console project, not a known exploitation framework module. Its primary implementation is ShieldBreak.cpp (about 47 KB); the remaining listed files are Visual Studio solution/project metadata, a resource-ID header, README, and license. The project is configured for Win32 and x64 Debug/Release builds and links against ntdll, CldApi, onecore, and Task Scheduler libraries. The source defines Microsoft Defender-related internal data types and uses Windows Cloud Files APIs, COM Task Scheduler interfaces, Windows Error Reporting task execution, resource extraction, and a named pipe. It embeds or expects ZIP and DLL resources and cleans up the synchronization root, WER files/directories, scan target, and pipe after execution. No remote host, URL, IP address, DNS name, or external C2 endpoint is present in the supplied code. The project metadata references ShieldBreak.rc plus several binary/resource inputs that are absent from the eight-file listing, meaning the repository as provided may not build without those missing artifacts. The README attributes the technique to CVE-2026-50656 and claims a Defender patch bypass, but the claim and the behavior of the unavailable embedded DLL cannot be independently verified from the supplied contents.
This repository is a Windows-focused local exploit PoC for CVE-2026-50656, described as a Microsoft Defender patch bypass ('ShieldBreak'). The repo is small and centered around a single substantial C++ source file, ShieldBreak-MSNightmare/ShieldBreak.cpp, plus Visual Studio project files, a resource header, and documentation. The top-level README mainly wraps and references the upstream ShieldBreak project, while the nested ShieldBreak-MSNightmare directory contains the actual exploit implementation. The exploit is not a framework module and appears to be a standalone Visual Studio C++ application. Its code imports numerous Windows-specific APIs and libraries including ntdll, Cloud Files API (cfapi), COM/OLE, ACL APIs, and Task Scheduler interfaces. The visible code shows embedded resources for a ZIP and DLL, suggesting the executable carries staged artifacts internally. Project metadata further references eicar_com.zip, Report.wer, ShellDll.dll, and Warden.dll, indicating the exploit likely uses a Defender-detectable sample plus one or more DLL payloads and a crafted WER report. Operationally, the exploit appears to be a local attack chain rather than a remote/network exploit. It creates files and directories, interacts with Cloud Files sync-root functionality, sets up a named pipe for synchronization, and uses COM to connect to the Windows Task Scheduler service. It specifically opens the task folder '\Microsoft\Windows\Windows Error Reporting', retrieves the 'QueueReporting' task, and runs it. This strongly suggests the exploit abuses Windows Error Reporting task execution as part of the bypass chain. After successful execution it prints '[+] Exploit succeeded.' and performs cleanup by disconnecting/unregistering the sync root and deleting staged files/directories. No external network C2, hardcoded IPs, or remote URLs are present in the exploit code shown. The notable fingerprintable targets are local Windows components: the Windows Error Reporting scheduled task path, temporary/staged files, embedded DLL/ZIP resources, and named-pipe-based IPC. Overall, this is a real exploit PoC with embedded payload/staging capability, intended to demonstrate a local Defender bypass on modern Windows systems rather than merely detect the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
258 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The underlying RoguePlanet vulnerability addressed by the August 2026 Patch Tuesday updates. ShieldBreak reportedly bypasses its patch. The content recommends applying August cumulative updates to address RoguePlanet but does not separately explain its technical mechanism.
A race-condition zero-day affecting Microsoft Defender that was publicly disclosed in June 2026 and patched on July 19, 2026; later bypassed by ShieldBreak.
A previously disclosed vulnerability in Microsoft software whose patch was bypassed by ShieldBreak.
A Microsoft Defender race-condition zero-day vulnerability that Microsoft patched on July 19, 2026; subsequent ShieldBreak and ShieldCrash exploits are described as bypasses of the associated fixes.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.