CVE Tools

Nightmare Eclipse раскрыл 0-day-уязвимость ShieldBreak, которая затрагивает Microsoft Defender

Хакер (xakep.ru)By Мария Нефёдова

PoC publicMicrosoft DefenderWindows 10

Our summary

Researcher Nightmare Eclipse has published a working proof-of-concept exploit for a new zero-day vulnerability dubbed ShieldBreak, which allows local attackers to escalate privileges to SYSTEM on fully patched systems. The flaw functions as a complete bypass for CVE-2026-50656 (CVSS 7.8), a race condition previously fixed in Microsoft Defender, by hooking user-mode callback functions during Cloud Filter API scans to alter file contents.

While the demonstrated exploit successfully targets Windows 11 25H2 and Windows Server 2025 with reported 100% success rates, the researcher notes that Windows 10 is also vulnerable despite the current PoC not supporting it. This release arrives shortly after Microsoft’s August Patch Tuesday, where they addressed CVE-2026-62832 (LegacyHive), continuing an ongoing dispute between the researcher and Microsoft’s Security Response Center regarding coordinated disclosure practices.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store