← All stories
● Covered by 4 sources · 5 reportsMedium impact2 negative3 neutral

New 'ShieldBreak' Zero-Day Exploit Bypasses Microsoft Defender Patch, Grants SYSTEM Privileges

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • "ShieldBreak" is a new zero-day exploit for Microsoft Defender.
  • It bypasses the patch for the RoguePlanet vulnerability (CVE-2026-50656).
  • The exploit grants SYSTEM privileges on Windows 10, 11, and Server 2025.
  • Security researcher Nightmare Eclipse released the proof-of-concept.
  • Windows Defender must be enabled for the exploit to work.

New Exploit Bypasses Defender Patch

Security researcher Nightmare Eclipse has released a new zero-day exploit named "ShieldBreak." This exploit targets Microsoft Defender and is described as a bypass for the previously disclosed RoguePlanet vulnerability, tracked as CVE-2026-50656. The release occurred after Microsoft's August 2026 Patch Tuesday security updates.

Grants SYSTEM Privileges on Windows Systems

ShieldBreak allows an attacker to gain SYSTEM privileges on fully patched Windows 10, Windows 11 (including version 25H2 and Canary channel), and Windows Server 2025 systems. The researcher claims a 100% success rate for the proof-of-concept on Windows 11 and Windows Server 2025, and states that Windows 10 is also vulnerable.

Security researcher Will Dormann confirmed that the exploit works and noted that Microsoft Defender must be enabled for the privilege escalation to occur.

RoguePlanet Patch Incomplete

Nightmare Eclipse stated that Microsoft failed to properly patch the RoguePlanet vulnerability, which was a race condition flaw in Defender initially disclosed as a zero-day in June. Microsoft acknowledged RoguePlanet on June 16 and released fixes on July 9. ShieldBreak demonstrates that the July patch was incomplete, allowing the vulnerability to be re-exploited.

Context of Previous Disclosures

Nightmare Eclipse has released multiple zero-day exploits targeting Microsoft products in recent months, often shortly after Patch Tuesday updates. This includes the "LegacyHive" Windows zero-day (CVE-2026-62832), which Microsoft patched in its August 2026 updates. LegacyHive allowed local attackers to gain administrator privileges through improper link resolution in the Windows User Profile Service.

Potential for Detection and Patching

While the exploit is confirmed to work by some researchers, there are indications that Microsoft may be addressing it. Some reports suggest that Microsoft Defender might already detect the ShieldBreak exploit, and a patch could have been included in a recent update.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Microsoft released security patches for the LegacyHive Windows zero-day vulnerability, tracked as CVE-2026-62832, as part of its August Patch Tuesday updates. This vulnerability, disclosed by a security researcher, allows local attackers to gain administrator privileges through improper link resolution in the Windows User Profile Service. The patch addresses a critical flaw that could lead to unauthorized data access and privilege escalation.

A new Windows zero-day vulnerability named ShieldBreak has been published, allowing a regular user to gain SYSTEM-level privileges. While the exploit is reported to affect recent Windows versions, Microsoft may have already patched it in a recent update and added Defender detection.

Security researcher Nightmare Eclipse released a new zero-day exploit called 'ShieldBreak' that allows privilege escalation on Windows by targeting Microsoft Defender. This exploit enables any user to gain System privileges on Windows 11, Windows Server 2025, and likely Windows 10, posing a significant security risk.

A security researcher, Nightmare Eclipse, has publicly disclosed a new zero-day vulnerability named "ShieldBreak" in Windows, allowing system-wide access, despite previous legal threats from Microsoft. This bug exploits Windows Defender and affects Windows 10, 11, and Server 2025, demonstrating a bypass of a prior patch for a related exploit.

A security researcher released "ShieldBreak," a new zero-day exploit for Microsoft Defender that bypasses a previous patch for the RoguePlanet vulnerability, allowing SYSTEM privileges on Windows 10, 11, and Server systems. This exploit highlights ongoing issues with Microsoft's vulnerability patching and disclosure practices, as it allows privilege escalation on fully updated systems.