CVE Tools
Back to feed
PoC public Microsoft Defender zero-day Windows 10 Microsoft privilege-escalation

Nightmare Eclipse раскрыл 0-day-уязвимость ShieldBreak, которая затрагивает Microsoft Defender

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Researcher Nightmare Eclipse has published a working proof-of-concept exploit for a new zero-day vulnerability dubbed ShieldBreak, which allows local attackers to escalate privileges to SYSTEM on fully patched systems. The flaw functions as a complete bypass for CVE-2026-50656 (CVSS 7.8), a race condition previously fixed in Microsoft Defender, by hooking user-mode callback functions during Cloud Filter API scans to alter file contents.

While the demonstrated exploit successfully targets Windows 11 25H2 and Windows Server 2025 with reported 100% success rates, the researcher notes that Windows 10 is also vulnerable despite the current PoC not supporting it. This release arrives shortly after Microsoft’s August Patch Tuesday, where they addressed CVE-2026-62832 (LegacyHive), continuing an ongoing dispute between the researcher and Microsoft’s Security Response Center regarding coordinated disclosure practices.