A serious security flaw has been discovered in Microsoft Defender — the built-in antivirus on all Windows computers — that allows an attacker to take complete control of an affected system. Microsoft has confirmed the issue and says a fix is in development, but no patch is available yet.
- What it is: A zero-day vulnerability (CVE-2026-50656, nicknamed "RoguePlanet") in Microsoft Defender's scanning engine. It exploits a timing flaw in how Defender processes files, allowing an attacker to swap a harmless file for a malicious one mid-scan.
- Who is affected: All Windows users running Microsoft Defender, which is installed by default on Windows 10 and Windows 11. The flaw works whether Defender's real-time protection is turned on or off.
- What is the risk: A working public exploit already exists. If an attacker can get you to open a malicious file — for example, via a phishing email or a compromised download — they can use this vulnerability to gain full SYSTEM-level control of your computer.
- What to do now: No patch is available yet. In the meantime, we recommend extra caution with email attachments and downloads, ensuring staff do not open unexpected files, and keeping all other security layers (email filtering, endpoint protection policies) up to date.
We are monitoring for Microsoft's patch release and will advise as soon as an update is available. Contact us if you have concerns about your exposure. Source: Help Net Security, The Hacker News.