Patch for Windows Defender 0-day could allow attackers to fill hard disk

Ars Technica News

Summary

Microsoft patched a zero-day vulnerability in Windows Defender (CVE-2026-50656) but the patch may cause disk space exhaustion due to a new bug that allows writing unlimited file sizes.

<p>A patch Microsoft released on Wednesday to fix a zero-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said.</p> <p>RoguePlanet, tracked as CVE-2026-50656, came to public notice <a href="%22https://deadeclipse666.blogspot.com%E2%80%9D/">in June</a> when NightmareEclipse, the pseudonymous name used by a researcher, disclosed it along with <a href="https://git.projectnightcrawler.dev/NightmareEclipse/RoguePlanet">code</a> for exploiting it. The vulnerability allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines, even when real-time protection has been disabled. Over the past few months, the anonymous researcher has published a <a href="https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/">handful</a> of <a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/">other</a> zero-days that have sent Microsoft scrambling to develop patches.</p> <h2>Writing files of unlimited size</h2> <p>Microsoft <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656">said</a> Wednesday that it patched RoguePlanet with an update to the Microsoft Malware Protection Engine, which is used by the Defender antivirus app. The fix will automatically be downloaded and installed without users having to take any action. Wednesday’s update also includes “defense-in-depth updates to help improve security-related features.”</p><p><a href="https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/">Read full article</a></p> <p><a href="https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/#comments">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 07/09/26, 10:40 PM

# Patch for Windows Defender 0-day could allow attackers to fill hard disk Source: [https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/](https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/) A patch Microsoft released on Wednesday to fix a zero\-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said\. RoguePlanet, tracked as CVE\-2026\-50656, came to public notice[in June](https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/%22https://deadeclipse666.blogspot.com%E2%80%9D/)when NightmareEclipse, the pseudonymous name used by a researcher, disclosed it along with[code](https://git.projectnightcrawler.dev/NightmareEclipse/RoguePlanet)for exploiting it\. The vulnerability allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines, even when real\-time protection has been disabled\. Over the past few months, the anonymous researcher has published a[handful](https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/)of[other](https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/)zero\-days that have sent Microsoft scrambling to develop patches\. ## Writing files of unlimited size Microsoft[said](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656)Wednesday that it patched RoguePlanet with an update to the Microsoft Malware Protection Engine, which is used by the Defender antivirus app\. The fix will automatically be downloaded and installed without users having to take any action\. Wednesday’s update also includes “defense\-in\-depth updates to help improve security\-related features\.” In a[post](https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/)on Thursday, NightmareEclipse said the defense\-in\-depth additions produce behavior that may allow attackers to exhaust all available space on a hard drive by writing massive amounts of data to it\. The newly introduced mitigations create a problem in mpengine\.dll, the driver associated with the Microsoft Malware Protection Engine, that in some cases causes it to leak 8 bytes of data when trying to open a file\. New functionality in[SpyNet](https://www.thewindowsclub.com/what-is-microsoft-spynet), a cloud service that allows Microsoft Security Essentials or Forefront Endpoint Protection to send reports about suspicious software and programs to Microsoft, also plays a role in the potential mass file\-writing behavior\. Defender normally places hard limits on how big a file can be written to disk when scanning and quarantining a machine\. “This implementation make \[sic\] sense, because quarantining a huge file will cause Defender to completely exhaust the available disk space,” the researcher wrote\. “I found a small exception to this rule, apparently the spynet functions in mpengine\.dll really wants \[sic\] to keep a local copy of Zone\.Identifier ADS file and it does not matter how big this file is, Windows Defender will cache it locally anyways\.”

Similar Articles

Patch Tuesday, April 2026 Edition

Krebs on Security

Microsoft's April 2026 Patch Tuesday fixes a record 167 vulnerabilities, including an actively exploited SharePoint zero-day and a publicly disclosed Windows Defender bug (BlueHammer), while Google Chrome and Adobe Reader also addressed zero-days.

Microsoft Plugs Nearly 400 Security Holes

Krebs on Security

Microsoft released patches for nearly 400 security vulnerabilities, including one actively exploited zero-day, as AI-driven discovery continues to swell patch volumes.

Microsoft Patches a Record 570 Security Flaws

Krebs on Security

Microsoft released a record 570 security patches for Windows and other software, including 60 critical flaws and three zero-days, attributing the increase to AI-assisted vulnerability discovery.