tag
Windows-Defender
Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks
ShieldBreak is a 0-day local privilege escalation exploit that bypasses the patch for CVE-2026-50656 (RoguePlanet), achieving SYSTEM-level code execution from an unprivileged user on fully patched Windows 11 and Server 2025 systems. The exploit was released…
CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface)
CVE-2026-50656 is a High-severity Elevation of Privilege vulnerability in the Microsoft Malware Protection Engine, publicly referred to as RoguePlanet. It stems from improper link resolution before file access (CWE-59) — the engine follows attacker-controlled…
RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition
RoguePlanet is a local privilege escalation exploit for Windows 10 and 11 that abuses a race condition in Windows Defender's scan pipeline. The exploit mounts an attacker-controlled ISO image via the VirtualDisk API, plants an EICAR-like trigger file inside…
RedSun Privileged File Write (CVE-2026-33825)
RedSun documents a local privilege-escalation technique where Defender's handling of a cloud-tagged malicious file can be abused as a privileged file write primitive. The PoC orchestrates file operations so the antimalware rewrite path lands on a high-value…
BlueHammer Defender Local Privilege Escalation (CVE-2026-33825)
BlueHammer is a Windows local privilege-escalation PoC targeting Defender-associated update and scanning behavior. The exploit orchestrates object-manager symbolic links, directory change notifications, oplocks, RPC-triggered Defender activity, and…