Microsoft Defender zero-day ‘ShieldBreak’ grants SYSTEM access

▼ Summary
– Security researcher Nightmare Eclipse released a new Microsoft Defender zero-day exploit named ShieldBreak after the August 2026 Patch Tuesday, which bypasses the RoguePlanet vulnerability (CVE-2026-50656) that Microsoft failed to properly patch.
– ShieldBreak uses a user-mode callback hook to alter file contents during a Defender cloud-hydration scan via the Cloud Filter API, differing from RoguePlanet’s filesystem race condition that manipulated virtual disks to overwrite system files.
– The exploit grants SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems, with a 100% success rate on Windows 11 25H2 and Windows Server 2025, though Windows 10 is vulnerable but unsupported in the proof-of-concept.
– Cybersecurity expert Kevin Beaumont and principal vulnerability analyst Will Dormann confirmed the exploit works, which requires Microsoft Defender to be enabled for privilege escalation.
– The disclosure is part of a dispute with Microsoft over its vulnerability disclosure and bug bounty practices, with Microsoft warning of legal action for malicious activity and stating it is investigating the claims while supporting coordinated vulnerability disclosure.
A security researcher operating under the alias Nightmare Eclipse has publicly released a new zero-day exploit for Microsoft Defender, dubbed “ShieldBreak,” arriving just after the August 2026 Patch Tuesday rollout. The exploit functions as a direct bypass for a previously disclosed privilege escalation flaw known as RoguePlanet, which Microsoft patched in July.
While the two vulnerabilities share a target, their technical mechanisms diverge significantly. Cybersecurity expert Kevin Beaumont, who has also published detection queries for ShieldBreak within Microsoft Defender for Endpoint, clarified the distinction. “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”
According to Nightmare Eclipse, ShieldBreak successfully elevates privileges to SYSTEM on fully patched iterations of Windows 10, Windows 11, and Windows Server. The researcher asserts that Microsoft’s earlier fix for CVE-2026-50656 was incomplete. “Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” they stated.
The proof-of-concept has been validated on Windows 11 25H2, including the Canary channel, and Windows Server 2025, with the researcher reporting a 100% success rate. While Windows 10 and its server counterparts are not currently supported by the PoC, they remain susceptible to the same flaw. Will Dormann, principal vulnerability analyst at Tharros, confirmed the exploit’s functionality on Tuesday, noting that Microsoft Defender must be active for the attack to succeed.
This release marks another chapter in an escalating conflict between Microsoft and Nightmare Eclipse regarding disclosure policies and bug bounty compensation. Microsoft has previously cautioned researchers about potential legal consequences for “malicious activity causing real harm,” a statement many in the security community interpreted as a direct threat aimed at this specific researcher.
Since April 2026, Nightmare Eclipse has unveiled a string of zero-days, including LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, targeting Microsoft Defender, BitLocker, and other Windows components. Although Microsoft addressed RoguePlanet in July and fixed YellowKey, GreenPlasma, and MiniPlasma during the June 2026 Patch Tuesday, several other disclosed vulnerabilities remain unpatched.
In response to inquiries about ShieldBreak, a Microsoft spokesperson told BleepingComputer that the company is “aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims.” They emphasized a commitment to securing customers and supporting coordinated vulnerability disclosure, an industry standard that ensures findings are thoroughly examined before public release.
(Source: BleepingComputer)
