
A security researcher has disclosed a new Windows Defender vulnerability that can allow an attacker to escalate from a low-privileged user account to system-level access. The flaw, named ShieldBreak, affects recent versions of Windows and was published without giving Microsoft advance time to release a patch.
The researcher, known as Nightmare Eclipse, published a proof-of-concept Windows application demonstrating the issue. According to the project page, ShieldBreak has been tested on Windows 11 version 25H2, Windows Server 2025, and other current Windows builds.
Security researcher Will Dormann separately verified that the exploit works when Microsoft Defender is enabled. Microsoft told TechCrunch that it is aware of the reported vulnerability and is investigating whether the claims are valid and applicable.
ShieldBreak Bypasses an Earlier Microsoft Fix
ShieldBreak builds on an earlier vulnerability called RoguePlanet, according to Nightmare Eclipse. Microsoft previously addressed RoguePlanet as CVE-2026-50656, but the researcher said ShieldBreak demonstrates that the earlier fix can be bypassed.
A successful attack requires the victim to run the proof-of-concept application. Once executed, the flaw in Windows Defender can allow the process to move from restricted user privileges to broad control over the machine and its data.
Microsoft has not released a dedicated ShieldBreak patch as of August 13. That makes the vulnerability a zero-day under Microsoft’s own definition because no official security update is currently available for the newly disclosed flaw.
Disclosure Follows Dispute Over Microsoft’s Bug Reporting Process
The release follows months of public disagreement between Nightmare Eclipse and Microsoft over how vulnerability reports were handled. The researcher has previously published several Windows flaws after alleging that Microsoft did not respond adequately to submitted reports.
In May, Microsoft published an official statement on coordinated vulnerability disclosure, arguing that researchers should provide vendors with time to investigate and fix vulnerabilities before publishing technical details. Microsoft said releasing zero-days without prior notice can expose customers to unnecessary risk.
The company faced criticism from security researchers after the post referred to potential legal consequences for certain disclosures. Microsoft later softened its public position in a social media statement, although the original blog post remains online.
ShieldBreak was published one day after Microsoft’s August Patch Tuesday release. Microsoft issued another large set of security fixes this month, continuing a pattern of unusually high vulnerability counts that the company has partly attributed to increased use of AI and automation in software security research.
Featured image credits: GitBit
For more stories like it, click the +Follow button at the top of this page to follow us.
