Microsoft Defender Exploit 'ShieldBreak' Grants SYSTEM Privileges
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called 'ShieldBreak' that can grant SYSTEM privileges on fully patched Windows systems.
The exploit, which was tested on the latest version of Windows 11 and Windows Server 2025, has a 100% success rate in escalating attackers' privileges. Nightmare Eclipse claims that Microsoft failed to properly patch the RoguePlanet vulnerability, CVE-2026-50656, which was disclosed in June and patched by Microsoft one month later.
Will Dormann, principal vulnerability analyst at Tharros, confirmed on Tuesday that the exploit works, stating that Microsoft Defender needs to be enabled for the ShieldBreak exploit to escalate attackers' privileges. This is the latest development in an ongoing dispute between Microsoft and Nightmare Eclipse over the company's vulnerability disclosure and bug bounty practices.
The ShieldBreak exploit is part of a series of zero-day exploits disclosed by Nightmare Eclipse since April 2026, including vulnerabilities in Microsoft Defender, BitLocker, and various Windows components. While some of these vulnerabilities have been patched, others are still waiting for an official fix.