PoC Archive PoC Archive

tag

Windows-Defender

  • Bypass of CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks

    ShieldBreak is a 0-day local privilege escalation exploit that bypasses the patch for CVE-2026-50656 (RoguePlanet), achieving SYSTEM-level code execution from an unprivileged user on fully patched Windows 11 and Server 2025 systems. The exploit was released…

    Unpatched 2026-08-11
  • CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface)

    CVE-2026-50656 is a High-severity Elevation of Privilege vulnerability in the Microsoft Malware Protection Engine, publicly referred to as RoguePlanet. It stems from improper link resolution before file access (CWE-59) — the engine follows attacker-controlled…

    Patched 2026-06-26
  • CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition

    RoguePlanet is a local privilege escalation exploit for Windows 10 and 11 that abuses a race condition in Windows Defender's scan pipeline. The exploit mounts an attacker-controlled ISO image via the VirtualDisk API, plants an EICAR-like trigger file inside…

    Unpatched 2026-06-10
  • CVE-2026-33825 binary HIGH 7.8 KEV Ransomware

    RedSun Privileged File Write (CVE-2026-33825)

    RedSun documents a local privilege-escalation technique where Defender's handling of a cloud-tagged malicious file can be abused as a privileged file write primitive. The PoC orchestrates file operations so the antimalware rewrite path lands on a high-value…

    Patched 2026-05-15
  • CVE-2026-33825 binary HIGH 7.8 KEV Ransomware

    BlueHammer Defender Local Privilege Escalation (CVE-2026-33825)

    BlueHammer is a Windows local privilege-escalation PoC targeting Defender-associated update and scanning behavior. The exploit orchestrates object-manager symbolic links, directory change notifications, oplocks, RPC-triggered Defender activity, and…

    Patched 2026-05-15