CVE-2026-50656

malware_protection_engine: Improper Link Resolution Before File Access ('Link Following') (CVE-2026-50656)

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

microsoftmalware_protection_engine

Metrics

7.8
Source: cna-v3
28.6 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
PoC (publicly reported)
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-06-16 18:01 UTC
CWE-59

Weakness classes (CWE)

  • CWE-59Base

    Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-09 00:17 UTC· secure@microsoft.com
    • Affected: Microsoft Malware Protection Engine → Microsoft Malware Protection Engine
    • Description: Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. → Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;.
  2. New CVE Received2026-06-16 19:16 UTC· secure@microsoft.com
    • Description: Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
    • CVSS V3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-59
    • Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656

Linked advisories