VECTOR WIREAI INTELLIGENCE
NVDA$1,847+3.2%MSFT$512+1.1%GOOGL$199-0.4%META$728+2.7%AMD$184-1.2%TSM$212+0.6%PLTR$98+4.1%AI IDX4,821+1.9%
PKT
SEEDRefresh Models Deals Regulatory Sources

ShieldBreak Zero-Day Bypasses Microsoft Defender Patch, Grants SYSTEM Privileges

A researcher released ShieldBreak, a zero-day exploit bypassing Microsoft Defender's CVE-2026-50656 patch to grant SYSTEM privileges on fully patched…

Vector Wire — AI-assisted editorial illustration

A security researcher known as Chaotic Eclipse released a proof-of-concept exploit called ShieldBreak on August 12, targeting Microsoft Defender and granting SYSTEM-level privileges on fully patched Windows 10, Windows 11, and Windows Server systems1,2.

ShieldBreak is a bypass for CVE-2026-50656 (CVSS 7.8), the vulnerability behind the RoguePlanet privilege escalation flaw disclosed in June and patched by microsoft in July. Chaotic Eclipse — also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse — said microsoft "has failed to properly patch" the original vulnerability and that the new PoC "demonstrates a full patch bypass".

The researcher said the PoC was tested on Windows 11 25h2 (including the Canary channel) and Windows Server 2025 with a "100% success rate". Windows 10 and its corresponding server editions are not currently supported by the PoC but are also vulnerable, according to Chaotic Eclipse.

Cybersecurity expert Kevin Beaumont, who published ShieldBreak exploitation detection queries for Microsoft Defender for Endpoint, said the two exploits work through distinct mechanisms. Beaumont described RoguePlanet as "a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files". ShieldBreak, by contrast, uses "a user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API)," Beaumont said.

Will Dormann confirmed on August 12 that the ShieldBreak exploit works, noting that Microsoft Defender needs to be enabled for the exploit to escalate an attacker's privileges.

microsoft responded to Chaotic Eclipse's disclosures with warnings of legal action against people "engaging in malicious activity causing real harm to its customers".

ShieldBreak is the latest in a series of zero-day disclosures from the same researcher. Since April 2026, Chaotic Eclipse has disclosed LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend — zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components. microsoft fixed the RoguePlanet vulnerability in July and patched YellowKey, GreenPlasma, and MiniPlasma as part of the June 2026 Patch Tuesday. The remaining vulnerabilities disclosed by Chaotic Eclipse are still awaiting official patches.

ANALYSIS The distinct attack surface — abusing the Cloud Filter API during cloud-hydration scans rather than the filesystem race condition exploited by RoguePlanet — means that organizations that deployed the July patch believing the escalation path was closed remain exposed. The volume of zero-days from a single researcher since April 2026, with several still unpatched, compounds the exposure for enterprises relying on Microsoft Defender as a primary defense layer.

CORRECTIONS: none for this article · this piece updates automatically as the story develops · corrections policy & trail →