AIO APEX

Unpatched Microsoft Defender zero-day 'ShieldBreak' grants SYSTEM access on all Windows versions

BleepingComputer
Share:
Unpatched Microsoft Defender zero-day 'ShieldBreak' grants SYSTEM access on all Windows versions

A Defender Flaw That Patches Can't Stop

Security researcher "Nightmare Eclipse" released a working proof-of-concept exploit for a vulnerability in Microsoft Defender called ShieldBreak (CVE-2026-69414) that can elevate any low-privilege local attacker to SYSTEM on fully patched Windows systems. Microsoft has no security update ready and has only confirmed it is "actively investigating," as first reported by BleepingComputer.

What ShieldBreak Does

ShieldBreak targets the Microsoft Malware Protection Engine — the scanning core inside Defender — specifically during cloud-file hydration. When Defender retrieves a file from cloud storage via the Windows Cloud Filter API (CFAPI), the exploit inserts a user-mode callback that substitutes different file contents mid-scan. Defender ends up scanning a different file than the one it retrieved, bypassing the integrity of the scan entirely.

Security expert Kevin Beaumont confirmed the mechanism: a user-mode callback hook changes the file contents during Defender's cloud-hydration scan via CFAPI. The researcher claims a 100% success rate on Windows 10, Windows 11 25H2 (including Canary channel builds), and Windows Server 2025.

A Bypass for a Bypass

ShieldBreak was specifically designed to circumvent the patch Microsoft issued in July 2026 for an earlier flaw called RoguePlanet (CVE-2026-50656). Where RoguePlanet exploited a filesystem race condition, ShieldBreak takes an entirely different path — the user-mode callback — to reach the same outcome. Nightmare Eclipse published the exploit without advance notice to Microsoft, citing an ongoing dispute over the company's bug bounty and vulnerability disclosure practices.

Who Is at Risk

Any Windows system with Microsoft Defender enabled is potentially vulnerable — which in practice means almost every Windows computer running default settings. Affected platforms include Windows 10, Windows 11 (all builds through 25H2 and the Canary channel), and Windows Server 2025. The vulnerability requires an attacker to already have local access; it is an elevation-of-privilege flaw, not remote code execution.

No Patch, No Timeline

Microsoft assigned CVE-2026-69414 with a CVSS score of 7.8 and an exploitability rating of "Exploitation More Likely," but has not released a fix or provided any timeline. Its statement said it is "working to provide a high quality security update that addresses this vulnerability."

CISA's Binding Operational Directive BOD 26-04 requires federal agencies to apply mitigations for exploited zero-days within 14 days of being added to the Known Exploited Vulnerabilities catalog. Non-federal organizations are advised to follow the same 14-day standard.

What to Do Now

With no official patch available, defenders should focus on detection rather than prevention: monitor for unusual SYSTEM-level process creation on endpoints, audit privileged access paths, and watch Microsoft Security Response Center advisories for patch releases. Because the proof-of-concept is already public, the window between initial disclosure and weaponization by threat actors is effectively closed.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: