Microsoft's Windows Defender Hit with Zero-Day Vulnerability
A recent vulnerability discovered by cybersecurity researcher Nightmare Eclipse has put Microsoft's Windows Defender under scrutiny. The flaw, dubbed ShieldBreak, allows an attacker to gain system-level control using privileged scanning capabilities in Windows Defender.
The exploit manipulates the Cloud Filter API during cloud hydration and uses mechanisms in the Common Log File System to swap file identity and hydration data. This enables an attacker-controlled DLL to be placed in a core Windows system folder, bypassing User Account Control and modifying System-level files.
MICROSOFT spokesperson confirmed awareness of the vulnerability and is investigating its validity and potential applicability. CERT Coordination Center's vulnerability analyst Will Dormann verified the proof-of-concept exploit, which triggers the privileged QueueReporting scheduled task used by Windows Error Reporting.