SECURITY Signal 421
Security researcher publishes Windows zero-day ShieldBreak despite Microsoft legal threat
Security researcher Nightmare Eclipse publicly disclosed a new Windows zero-day called ShieldBreak that allows privilege escalation via Windows Defender, continuing their release of unpatched vulnerabilities after Microsoft threatened legal action against such disclosures.
ShieldBreak affects Windows 10, Windows 11 including version 25H2, and Windows Server 2025, and requires only that Windows Defender be enabled and a user execute the proof-of-concept app. The disclosure highlights an ongoing conflict between security researchers and Microsoft over bug handling, where previously released zero-days by the same researcher were later exploited in real-world attacks.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
ShieldBreak exploits a flaw in Windows Defender to escalate privileges from a low-level user to full system access, and a proof-of-concept exploit has been published as a Windows app.
The vulnerability is a full bypass of an earlier patch for a bug called RoguePlanet, indicating Microsoft's original fix was insufficient.
Microsoft has not yet released a patch for ShieldBreak, and the disclosure comes a day after the company's monthly Patch Tuesday release.
THE CLUSTER
↗