Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-50656-rogueplanet-validation — Validation report for the RoguePlanet Microsoft Defender PoC in a controlled Windows 11 lab environment, including build notes, Defender detection results, risk assessment, and mitigation recommendations. | Kitploit
Tools/GitHubGitHub/g0thamrabb1t/cve-2026-50656-rogueplanet-validation
Privilege EscalationVulnerability AnalysisExploitationMalware AnalysisPenetration TestingLearning & EducationBinary ExploitationLabs & Practice

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
g0thamrabb1t/cve-2026-50656-rogueplanet-validation

CVE-2026-50656-rogueplanet-validation

Validation report for the RoguePlanet Microsoft Defender PoC in a controlled Windows 11 lab environment, including build notes, Defender detection results, risk assessment, and mitigation recommendations.

View Repository
273 months agoNot yet reviewed

RoguePlanet PoC Validation Report for Microsoft Defender

Purpose and scope of the report

This report concerns the validation of the publicly described RoguePlanet PoC related to Microsoft Defender. The described technique was presented in the media on 10 June 2026 as a Local Privilege Escalation (LPE), in which a local user can obtain NT AUTHORITY\SYSTEM privileges. Public descriptions indicated that the mechanism uses functions used by Microsoft Defender when handling or scanning a file.

The purpose of the test was to determine whether the exploit could be prepared and executed in a controlled laboratory environment, and to observe how Microsoft Defender protection mechanisms behave on an up-to-date Windows 11 system. The report covers the test environment, update status, Microsoft Defender configuration, preparation of the compilation environment, compilation result, Defender response, and risk-reduction recommendations.

The test was research-oriented and was performed locally on a dedicated test workstation. The results should be interpreted as an assessment of the behavior of a specific artifact and a specific environment configuration, not as full confirmation of resistance to all possible variants of this technique.

Sources referenced in the analyzed material:

  • Article:

    https://thehackernews.com/2026/06/microsoft-defender-rogueplanet-zero-day.html

  • Public PoC repository:

    https://github.com/MSNightmare/RoguePlanet/tree/main

  • MSYS2 installer source:

    https://github.com/msys2/msys2-installer/releases/tag/nightly-x86_64

  • Visual Studio source:

    https://visualstudio.microsoft.com/insiders/?rwnlp=pl

Test environment

The PoC was performed on a client workstation operating outside an Active Directory domain, in the WORKGROUP workgroup. The operating system installed on the workstation was Microsoft Windows 11 Home, version 25H2, 64-bit architecture.

ParameterValue
System nameMicrosoft Windows 11 Home
EditionHome
System version25H2
OS version10.0.26200
Build number26200
Architecturex64 / 64-bit
Installation typeClient / Workstation
Host nameLAPTOP-80LPIEH2
Device manufacturerLenovo
Device modelLenovo Legion Slim 5 16IRH8
Processor12th Gen Intel(R) Core(TM) i5-12450H
RAM32 GB

On the day the PoC was performed, the system had the June 2026 security updates installed, as well as earlier updates from May and April 2026. This means that the test was carried out on an up-to-date Windows 11 25H2 system, build 26200, after installation of the latest available security patches as of the test date.

HotFixIDUpdate typeInstallation date
KB5094135Security Update10.06.2026
KB5094126Security Update10.06.2026
KB5087051Update14.05.2026
KB5092762Security Update13.05.2026
KB5054156Update28.04.2026

Microsoft Defender configuration

Microsoft Defender Antivirus was active on the workstation used for the test and was running in normal mode. The protection service was running and enabled, and antivirus protection, antispyware protection, behavior monitoring, and real-time protection were active.

ParameterValue
AMProductVersion4.18.26050.15
AMServiceVersion4.18.26050.15
AMEngineVersion1.1.26050.11
AMRunningModeNormal
AMServiceEnabledTrue
AntivirusEnabledTrue
AntispywareEnabledTrue
RealTimeProtectionEnabledTrue
BehaviorMonitorEnabledTrue
OnAccessProtectionEnabledTrue
IoavProtectionEnabledTrue
NISEnabledTrue
NISEngineVersion1.1.26050.11
IsTamperProtectedTrue
DefenderSignaturesOutOfDateFalse
RebootRequiredFalse
IsVirtualMachineFalse

On the day of the test, Microsoft Defender signatures were up to date. Antivirus, antispyware, and NIS signatures had been updated on 10.06.2026 at 13:27:32.

Signature typeVersionLast update date
AntivirusSignatureVersion1.453.27.010.06.2026 13:27:32
AntispywareSignatureVersion1.453.27.010.06.2026 13:27:32
NISSignatureVersion1.453.27.010.06.2026 13:27:32

The last quick scan was performed on 08.06.2026 between 15:00:36 and 15:01:58, using signatures version 1.451.323.0. A full scan had not been performed previously or its history was not available, as indicated by the FullScanAge value of 4294967295 and the absence of full scan start and end times.

Preparation of the compilation environment

The first attempt to compile the code from the GitHub repository ended with an error caused by the missing winternl.h header. The message indicated that the system did not have the complete set of Windows SDK headers required by the analyzed code.

Figure 1. Missing winternl.h header error during the first compilation attempt.

The code also referenced other headers related to Windows API and NT API, including windows.h, Psapi.h, ntstatus.h, virtdisk.h, shlwapi.h, taskschd.h, and bcrypt.h. For this reason, it was necessary to prepare a more complete compilation environment and install the appropriate SDK components.

Figure 2. Fragment of the list of headers required by the analyzed code.

Attempt to use MSYS2/MinGW-w64

Initially, MSYS2/MinGW-w64 was used to prepare the compilation environment. This environment provides GNU tools for Windows, including the gcc and g++ compilers. Packages in MSYS2 are managed using pacman, which serves a similar role to apt on Linux systems or winget on Windows.

Figure 3. Completion of the MSYS2 installation.

Using pacman, the MinGW-w64 GCC/G++ toolchain was installed, i.e. a set of tools that enables compilation of C/C++ code for Windows. The package includes, among other components, the gcc compiler, the g++ C++ compiler, the linker, and the headers and libraries required to build applications running in the Windows environment. The purpose of this attempt was to check whether the code could be compiled using the open toolchain available in MSYS2, without using Visual Studio.

Download Tool