CVE Tools

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

SecurityWeekBy Ionut Arghire

PoC publicMicrosoft DefenderWindows 11

Our summary

Security researcher Nightmare Eclipse has published the proof-of-concept exploit 'ShieldBreak' for CVE-2026-50656, a vulnerability in Microsoft Defender that enables local privilege escalation to System level. The exploit affects recent versions of Windows 11 and Windows Server 2025, and researchers indicate it likely impacts Windows 10 systems as well. While described by the researcher as a bypass to the earlier RoguePlanet flaw, technical analysts note that ShieldBreak operates via Cloud Filter API hooks rather than the filesystem race condition used in its predecessor.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store