ShieldBreak Windows zero-day bypasses earlier Defender fix

Security researcher Nightmare Eclipse has published ShieldBreak, a Windows zero-day that can elevate a low-privilege user to full access to a device and its data. The proof-of-concept was released as a Windows application and is said to affect Windows 10, Windows 11 including version 25H2, and Windows Server 2025.
ShieldBreak exploits a flaw in Windows Defender, Microsoft’s built-in anti-malware and security engine. For the published exploit to succeed, a user must run the application. Security researcher Will Dormann verified that the issue works and that Windows Defender must be enabled for the exploit to function.
Defender flaw enables privilege escalation
The reported impact is a jump from a low-level user account to system-wide access. That level of elevation can expose the device and the data held on it, making the issue significant where users can be persuaded or allowed to launch untrusted software.
Microsoft had not released a ShieldBreak patch at the time of publication and did not immediately comment. The disclosure arrived a day after the company’s scheduled monthly security releases, known as Patch Tuesday.
Researcher says RoguePlanet mitigation was bypassed
ShieldBreak builds on RoguePlanet, an earlier exploit developed by Nightmare Eclipse. Microsoft issued a fix for that issue, but ShieldBreak is presented as a complete bypass of the earlier patch. The prior Microsoft work on a Defender patch described Microsoft’s work on a Defender patch, while the new release raises questions about the sufficiency of that mitigation.
The issue is classed as a zero-day because Microsoft was not given time to patch it before public disclosure. It is part of an extended dispute between the researcher and Microsoft over the handling of vulnerability reports.
Nightmare Eclipse has said in blog posts that Microsoft mishandled the reports, while Microsoft warned in May that it could take legal action against researchers who disclosed zero-days outside its policies. The warning prompted criticism from security researchers, and Microsoft later softened the comments in a social-media post, although the original blog post remained online.
What organisations can do now
Until Microsoft publishes a fix, organisations should focus on controls already relevant to this proof-of-concept: restrict the execution of untrusted applications, maintain endpoint monitoring, and review alerts for suspicious privilege elevation. Security teams should also follow Microsoft’s update guidance so they can test and deploy a future ShieldBreak remediation promptly.

