ShieldBreak Zero-Day Vulnerability Exposes Windows Users to Full Device Control
A new zero-day vulnerability has been discovered in Windows Defender, allowing attackers to gain full control of a device and access user data.
Security researcher Nightmare Eclipse revealed the issue, dubbed ShieldBreak, which exploits a flaw in Windows Defender's privilege escalation mechanism. The vulnerability allows an attacker to escalate from a restricted user account to system-level access, giving them complete control over the device.
The disclosure came after Microsoft had warned that it might take legal action against researchers who publish information about zero-day vulnerabilities without complying with its responsible disclosure requirements.
Nightmare Eclipse claimed that the exploit works on Windows 10, Windows 11 (including version 25H2), and Windows Server 2025. The researcher also stated that RoguePlanet's protections can be completely bypassed by ShieldBreak.