New ShieldBreak Windows Defender Zero-Day Goes Public Before Microsoft Has a Patch
Security researcher Nightmare Eclipse disclosed a Windows Defender privilege-escalation vulnerability dubbed ShieldBreak that reportedly affects Windows 10, Windows 11 and Windows Server 2025, with no patch available at publication time.
Why it matters: An unpatched Defender privilege-escalation flaw is directly relevant to enterprise endpoint security because Defender is enabled across a vast Windows install base.
A newly disclosed vulnerability in Microsoft Windows Defender could allow an attacker who already has low-level access to a Windows account to escalate privileges and gain broad control of the affected device. The vulnerability, dubbed ShieldBreak, was publicly disclosed on August 12 by security researcher Nightmare Eclipse. The researcher says the flaw affects Windows 10, Windows 11 including version 25H2, and Windows Server 2025. Independent security researcher Will Dormann verified that the vulnerability works and that Microsoft Defender must be enabled for the attack to succeed. Microsoft had not released a patch specifically for ShieldBreak at the time of publication. The new disclosure is particularly notable because ShieldBreak builds on an earlier Defender exploit known as RoguePlanet. Microsoft issued a fix for RoguePlanet, but Nightmare Eclipse says the new technique bypasses that earlier remediation. ShieldBreak should not be characterized as a zero-click remote compromise. The currently demonstrated attack requires a user to run an application before privilege escalation can occur, and there is no confirmed evidence yet that ShieldBreak itself is being exploited in active attacks. For enterprise security teams, the disclosure is nevertheless significant because Defender is built directly into Windows and is widely deployed across corporate endpoints and servers.