CVE Tools
Back to feed
PoC public Microsoft Defender zero-day Windows 11 Microsoft privilege-escalation

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Security researcher Nightmare Eclipse has published the proof-of-concept exploit 'ShieldBreak' for CVE-2026-50656, a vulnerability in Microsoft Defender that enables local privilege escalation to System level. The exploit affects recent versions of Windows 11 and Windows Server 2025, and researchers indicate it likely impacts Windows 10 systems as well. While described by the researcher as a bypass to the earlier RoguePlanet flaw, technical analysts note that ShieldBreak operates via Cloud Filter API hooks rather than the filesystem race condition used in its predecessor.