Microsoft patched a zero-day vulnerability in Windows Defender (CVE-2026-50656) but the patch may cause disk space exhaustion due to a new bug that allows writing unlimited file sizes.
<p>A patch Microsoft released on Wednesday to fix a zero-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said.</p>
<p>RoguePlanet, tracked as CVE-2026-50656, came to public notice <a href="%22https://deadeclipse666.blogspot.com%E2%80%9D/">in June</a> when NightmareEclipse, the pseudonymous name used by a researcher, disclosed it along with <a href="https://git.projectnightcrawler.dev/NightmareEclipse/RoguePlanet">code</a> for exploiting it. The vulnerability allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines, even when real-time protection has been disabled. Over the past few months, the anonymous researcher has published a <a href="https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/">handful</a> of <a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/">other</a> zero-days that have sent Microsoft scrambling to develop patches.</p>
<h2>Writing files of unlimited size</h2>
<p>Microsoft <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656">said</a> Wednesday that it patched RoguePlanet with an update to the Microsoft Malware Protection Engine, which is used by the Defender antivirus app. The fix will automatically be downloaded and installed without users having to take any action. Wednesday’s update also includes “defense-in-depth updates to help improve security-related features.”</p><p><a href="https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/#comments">Comments</a></p>
# Patch for Windows Defender 0-day could allow attackers to fill hard disk
Source: [https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/](https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/)
A patch Microsoft released on Wednesday to fix a zero\-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said\.
RoguePlanet, tracked as CVE\-2026\-50656, came to public notice[in June](https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/%22https://deadeclipse666.blogspot.com%E2%80%9D/)when NightmareEclipse, the pseudonymous name used by a researcher, disclosed it along with[code](https://git.projectnightcrawler.dev/NightmareEclipse/RoguePlanet)for exploiting it\. The vulnerability allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines, even when real\-time protection has been disabled\. Over the past few months, the anonymous researcher has published a[handful](https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/)of[other](https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/)zero\-days that have sent Microsoft scrambling to develop patches\.
## Writing files of unlimited size
Microsoft[said](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656)Wednesday that it patched RoguePlanet with an update to the Microsoft Malware Protection Engine, which is used by the Defender antivirus app\. The fix will automatically be downloaded and installed without users having to take any action\. Wednesday’s update also includes “defense\-in\-depth updates to help improve security\-related features\.”
In a[post](https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/)on Thursday, NightmareEclipse said the defense\-in\-depth additions produce behavior that may allow attackers to exhaust all available space on a hard drive by writing massive amounts of data to it\. The newly introduced mitigations create a problem in mpengine\.dll, the driver associated with the Microsoft Malware Protection Engine, that in some cases causes it to leak 8 bytes of data when trying to open a file\. New functionality in[SpyNet](https://www.thewindowsclub.com/what-is-microsoft-spynet), a cloud service that allows Microsoft Security Essentials or Forefront Endpoint Protection to send reports about suspicious software and programs to Microsoft, also plays a role in the potential mass file\-writing behavior\.
Defender normally places hard limits on how big a file can be written to disk when scanning and quarantining a machine\.
“This implementation make \[sic\] sense, because quarantining a huge file will cause Defender to completely exhaust the available disk space,” the researcher wrote\. “I found a small exception to this rule, apparently the spynet functions in mpengine\.dll really wants \[sic\] to keep a local copy of Zone\.Identifier ADS file and it does not matter how big this file is, Windows Defender will cache it locally anyways\.”
A Windows 0-day vulnerability called LegacyHive allows non-admin users to escalate privileges by abusing how Windows loads user class hives, with Microsoft investigating and detection scripts available.
Microsoft's April 2026 Patch Tuesday fixes a record 167 vulnerabilities, including an actively exploited SharePoint zero-day and a publicly disclosed Windows Defender bug (BlueHammer), while Google Chrome and Adobe Reader also addressed zero-days.
Microsoft fixed a 0-day vulnerability disclosed by researcher Nightmare Eclipse amid a heated rivalry, alongside other vulnerabilities like MiniPlasma, YellowKey, and others. The researcher published exploit code for a new Windows Defender vulnerability.
Microsoft released patches for nearly 400 security vulnerabilities, including one actively exploited zero-day, as AI-driven discovery continues to swell patch volumes.
Microsoft released a record 570 security patches for Windows and other software, including 60 critical flaws and three zero-days, attributing the increase to AI-assisted vulnerability discovery.