
A new zero-day flaw in Windows Defender, named ShieldBreak, allows a local attacker to gain SYSTEM privileges on Windows 11, Windows 10, or Windows Server 2025 machines, even if fully updated. Microsoft has not yet released a patch.
A bypass of the July patch
ShieldBreak was published on August 12, 2026, by researcher Nightmare Eclipse, just hours after August’s Patch Tuesday. It exploits a vulnerability in Microsoft Defender to elevate a standard user’s privileges to SYSTEM level, the highest under Windows. According to its author, it bypasses the patch deployed in July for the RoguePlanet flaw (CVE-2026-50656), though experts like Kevin Beaumont note that the mechanisms of the two vulnerabilities differ.
The exploit takes the form of a Windows application to be executed locally. It works on Windows 11 25H2 and Windows Server 2025, and specifically targets a step in Defender’s operation where the antivirus downloads data from Microsoft’s servers. Independent researchers, including Will Dormann, have confirmed its effectiveness. Microsoft Defender must be enabled for the attack to succeed.
Microsoft under pressure, no patch in sight
Microsoft has acknowledged being aware of the vulnerability and is investigating its validity, but has not yet provided a patch. The flaw has also not been assigned a CVE identifier at this stage. In May 2026, the company had threatened legal action against researchers disclosing vulnerabilities without coordination, before softening its stance under pressure from the security community. Nightmare Eclipse, who has published nine zero-days since the start of the year, justifies public disclosures by Microsoft’s poor handling of vulnerability reports.
No active exploitation in real-world conditions has been reported so far. However, Kevin Beaumont has shared detection rules for Defender for Endpoint, allowing the identification of potential exploit use. Users are advised to apply the August Patch Tuesday (which does not fix ShieldBreak but addresses 398 other flaws), use an account without administrator rights, and avoid suspicious executables.
A limited but real risk
ShieldBreak is a local privilege escalation: it does not allow remote machine compromise but grants full access to an attacker already present on the system. Windows 10 versions not covered by the Extended Update Program are particularly exposed. The flaw adds to a series of critical vulnerabilities published by Nightmare Eclipse since April, some of which have already been exploited by cybercriminals.
“These disclosures expose our customers to unnecessary risks.” — Microsoft, in a post published in May 2026Translated from French
The race between Microsoft and security researchers remains endless. Pending a patch, best practices (updates, limited accounts, vigilance) remain the best defense. But the episode once again reminds us that an up-to-date PC is no longer synonymous with a protected PC.






Comments 0
Sign in to join the discussion.
Be the first to comment.