CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
PoC publicMicrosoft DefenderWindows 11Our summary
A public proof-of-concept has surfaced for ShieldBreak (CVE-2026-69414), a zero-day elevation-of-privilege flaw in the Microsoft Malware Protection Engine underlying Microsoft Defender. This vulnerability enables low-privileged local attackers to achieve full SYSTEM access by manipulating how Defender processes cloud-hydrated files via the Cloud Filter API. The exploit affects Windows 11 25H2 and Windows Server 2025, where attackers can abuse privileged processing paths to execute arbitrary code under high-trust contexts.
Below is the opening; the full story is at Qualys Security Blog.
From Qualys Security Blog
Executive Summary
ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection across Windows environments, and Qualys TruRisk Eliminate offers a mitigation that teams can apply now, with affected assets reassessable in VMDR to verify remediation.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.