CVE Tools

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

BleepingComputerBy Sergiu Gatlan

PoC publicMicrosoft Defender

Our summary

Researcher Nightmare Eclipse has published a proof-of-concept for "ShieldBreak," a Microsoft Defender vulnerability that allows privilege escalation to SYSTEM on fully patched Windows systems. This exploit functions as a bypass for the previously patched RoguePlanet flaw (CVE-2026-50656), effectively rendering the July security fix ineffective. The PoC has been verified to work with a high success rate on Windows 11 25H2, Windows 10, and Windows Server editions where Microsoft Defender is active.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store