CVE Tools
Back to feed
PoC public Microsoft Defender zero-day Microsoft privilege-escalation

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

Researcher Nightmare Eclipse has published a proof-of-concept for "ShieldBreak," a Microsoft Defender vulnerability that allows privilege escalation to SYSTEM on fully patched Windows systems. This exploit functions as a bypass for the previously patched RoguePlanet flaw (CVE-2026-50656), effectively rendering the July security fix ineffective. The PoC has been verified to work with a high success rate on Windows 11 25H2, Windows 10, and Windows Server editions where Microsoft Defender is active.