New exploit is said to grant SYSTEM through Microsoft Defender

The researcher known as Nightmare Eclipse released exploit code called ShieldBreak on 12 August 2026, shortly after Microsoft shipped its August updates. The code is said to grant SYSTEM privileges through Microsoft Defender, and the researcher describes it as a full bypass of the fix Microsoft issued in July for the RoguePlanet vulnerability, CVE-2026-50656. According to the researcher the code was tested on Windows 11 25H2, on the Canary channel and on Windows Server 2025, succeeding every time. Will Dormann, principal vulnerability analyst at Tharros, confirmed on 11 August that the exploit works, and states that Defender has to be enabled for privileges to be raised. BleepingComputer reports that Microsoft has been asked for comment.

What happens technically

Kevin Beaumont, who has also published detection queries for ShieldBreak in Microsoft Defender for Endpoint, describes the two vulnerabilities as working in entirely different ways. RoguePlanet was a filesystem race condition, in which virtual disks and low level file operations tricked the Defender quarantine process into overwriting system files. ShieldBreak takes another route: it hooks a user mode callback and changes the contents of a file while Defender scans it through the Cloud Filter API, the interface used when a file stored in the cloud is pulled down to the machine on demand.

The mechanism is worth understanding in principle, quite apart from this one flaw. An antivirus product has to read a file in order to judge it, and it does so with the highest privileges on the system. Files synchronised from the cloud also exist in two states, as a placeholder and as a complete file, and the transition between them happens the moment something reads the file. If an attacker manages to swap the contents in exactly that window, it is the privileged process that handles the new content. The security product then becomes the way in, not because it does anything wrong, but because it holds the privileges the attacker lacks.

There are limits to what has been confirmed. The claim that the code works on every patched machine, and that it succeeds every time, comes from the researcher. Dormann has confirmed that it works, with the caveat that Defender must be enabled. Windows 10 is, according to the researcher, not supported by the code but is said to be vulnerable all the same. The story also has a background worth knowing: this is a running dispute between Microsoft and the researcher over the company practices for disclosure and bug bounties, and since April 2026 the researcher has published a series of exploits against Defender, BitLocker and other parts of Windows. Some of the underlying flaws have been fixed, while others are still waiting for an update.

Ordinary accountno privilegesDefender scans filepulled from the cloudContent is swappedwhile the scan runsSYSTEM privilegeson a patched machine
Figure: The attack uses the moment when Defender reads a file being pulled down from the cloud. The content is swapped while the scan is running.

What this means for you if you run the Windows estate

This is not a case you can patch your way out of today, because there is no fix yet. What you can do is move your attention to where it belongs. A privilege escalation requires that someone is already running code as an ordinary user on the machine. That means the first step, whether phishing, a malicious installation or a hijacked session, is still the decisive link in the chain. If you make that step harder, it matters less that the last step is easy.

Berigo assesses that you should acquire detection rather than wait. Beaumont has published queries for Defender for Endpoint, and they can be deployed now. At the same time this is a reminder that your security product is part of your attack surface, not only a defence. Under NIS2 article 21 this belongs both in vulnerability handling and in monitoring, and a compensating measure is a valid answer as long as it is documented and time limited. We would add that a claim from a researcher is not the same as a vulnerability confirmed by the vendor, and that a board paper should say plainly which is which.

Berigo recommends

  • Deploy the published detection queries for Defender for Endpoint, and look back through history for hits.
  • Prioritise measures against the first step in the chain, code execution as an ordinary user, since no fix exists yet.
  • Watch Microsoft security advisories for an update, and plan the rollout before it arrives.
  • Treat security products as part of the attack surface in your risk assessment, not only as controls.
  • Separate the researcher claims clearly from what the vendor has confirmed when the case is taken to management.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch