A newly disclosed Microsoft Defender vulnerability, dubbed ShieldBreak, reportedly allows attackers to gain SYSTEM-level privileges on fully patched Windows devices. The proof-of-concept exploit was released after Microsoft’s August 2026 Patch Tuesday updates and is described as a bypass for an earlier Defender flaw.
ShieldBreak targets Microsoft Defender scans
Security researcher Nightmare Eclipse released the ShieldBreak zero-day as a proof of concept. According to the researcher, the vulnerability affects Windows 10, Windows 11 and Windows Server systems when Microsoft Defender is enabled.
The exploit reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 systems. Nightmare Eclipse claimed the proof of concept achieved a 100% success rate on the tested devices.
ShieldBreak zero-day exploitation could allow a local attacker to elevate privileges to SYSTEM. This is the highest privilege level on Windows and would give an attacker extensive control over an affected device.
The flaw differs from RoguePlanet
ShieldBreak has been described as a bypass for RoguePlanet, a Microsoft Defender privilege-escalation vulnerability disclosed in June 2026 and patched one month later.
However, security researcher Kevin Beaumont said the two flaws use different methods.
RoguePlanet involved a file-system race condition. It used virtual disks and low-level file operations to manipulate the Defender quarantine process and overwrite protected system files.
In contrast, ShieldBreak reportedly abuses a user-mode callback hook during a Defender cloud-hydration scan. The exploit uses the Windows Cloud Filter API, known as CfApi, to alter file content while Defender processes it.
Although the vulnerabilities have different technical mechanisms, both can lead to SYSTEM-level access when Microsoft Defender is active.
Independent researcher confirms the exploit works
Will Dormann, principal vulnerability analyst at Tharros, confirmed that the proof of concept functions as described. He noted that Microsoft Defender must be enabled for ShieldBreak zero-day exploitation to result in privilege escalation.
The disclosure adds to a series of Windows and Microsoft security flaws published by Nightmare Eclipse since April 2026.
Previous disclosures from the researcher have targeted Microsoft Defender, BitLocker and other Windows components. They include LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma and UnDefend.
Microsoft addressed RoguePlanet in its July security updates. It also patched YellowKey, GreenPlasma and MiniPlasma during June’s Patch Tuesday release.
Several other vulnerabilities disclosed by Nightmare Eclipse have not yet received an official Microsoft patch.
Microsoft has not announced a ShieldBreak fix
The ShieldBreak zero-day disclosure comes amid a public dispute between Microsoft and Nightmare Eclipse over vulnerability reporting and bug bounty practices.
Microsoft previously warned that it could take legal action against people involved in malicious activity that harms customers. Some security experts interpreted that statement as being directed at the researcher.
Microsoft had not announced a specific fix or security update for ShieldBreak at the time of publication.
Organisations should ensure that devices use layered security controls and monitor for signs of unusual privilege escalation. Security teams can also use published threat-hunting queries to look for potential ShieldBreak-related activity in Microsoft Defender for Endpoint environments.


0 responses to “New Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges”