Windows Defender Patch for RoguePlanet Zero-Day Vulnerability May Exhaust Disk Space on Windows Systems
Microsoft released a security update addressing the RoguePlanet zero-day vulnerability (CVE-2026-50656) in the Microsoft Malware Protection Engine used by Windows Defender. The flaw, disclosed earlier by researcher NightmareEclipse, allowed remote attackers to gain administrative control over Windows 10 and Windows 11 even when real-time protection was disabled. While the patch was intended to resolve the issue and deploy automatically, the researcher now claims it introduces a new problem involving excessive disk writes. Specifically, the update may cause Defender to cache extremely large Zone.Identifier alternate data streams without size limits, potentially filling the entire drive. The attack vector involves a malicious SMB server that serves oversized metadata streams while maintaining the connection. Microsoft has not yet confirmed the reported behavior, and tensions between the company and the researcher continue over disclosure practices and bug bounty rewards.
AntiMalware•Vulnerabilities & Exploits