Microsoft Investigates New Windows Zero-Day After Researcher Publishes ShieldBreak

Microsoft is investigating ShieldBreak, a Windows Defender zero-day that researchers say can give a local attacker SYSTEM-level privileges.

Aug 13, 2026 - 14:38
 6
Microsoft Investigates New Windows Zero-Day After Researcher Publishes ShieldBreak
Image Credit: Chatgpt

Microsoft is investigating a newly disclosed Windows vulnerability after a security researcher published proof-of-concept code demonstrating how the flaw could grant a local attacker SYSTEM-level privileges.

The vulnerability, dubbed ShieldBreak by researcher Nightmare Eclipse, affects Microsoft Defender, the security software built into Windows. Its disclosure extends an increasingly public dispute between the researcher and Microsoft over how previously unknown vulnerabilities should be reported and released.

ShieldBreak targets Microsoft Defender

According to Nightmare Eclipse, ShieldBreak can elevate a user operating with limited privileges to SYSTEM, the powerful Windows account used by the operating system and trusted services.

The researcher released a proof-of-concept Windows application demonstrating the issue. That distinction matters because ShieldBreak is a local privilege-escalation vulnerability rather than, based on the available evidence, a way for an unauthenticated attacker on the internet to compromise a Windows computer remotely.

An attacker would first need the ability to execute the exploit on the targeted system. If successful, however, SYSTEM privileges could provide extensive control over the machine.

Nightmare Eclipse said the vulnerability affects Windows 10, Windows 11 (including version 25H2), and Windows Server 2025. Security researcher Will Dormann independently tested the proof of concept and reported that the exploit worked when Microsoft Defender was enabled.

Researcher says ShieldBreak bypasses an earlier fix

ShieldBreak is connected to an earlier vulnerability the researcher called RoguePlanet. Microsoft issued a fix for that issue, but Nightmare Eclipse says ShieldBreak demonstrates that the mitigation can be bypassed.

Microsoft has not released a dedicated fix for ShieldBreak as of the disclosure. Because details and exploit code became public before Microsoft had an opportunity to address the newly reported issue, it is being treated as a zero-day vulnerability.

Microsoft said it was reviewing the claims rather than immediately confirming the vulnerability.

“We are aware of the reported vulnerability and are actively investigating the validity and potential applicability of these claims,” a Microsoft spokesperson said.

Until that investigation is complete, some of the technical details and the full range of affected Windows configurations remain claims from the researcher rather than findings confirmed by Microsoft.

Disclosure follows dispute between Microsoft and security researchers

The release comes amid broader tensions over vulnerability disclosure. Nightmare Eclipse has previously accused Microsoft of mishandling vulnerability reports and has publicly released information about other Windows security flaws.

Microsoft addressed uncoordinated zero-day disclosures in a May 27 post from its Security Response Centre. The company said several vulnerabilities had recently been published without being shared with Microsoft in advance, leaving its security teams to investigate and develop protections after the technical information was already public.

Microsoft argues that coordinated vulnerability disclosure gives software vendors time to understand and mitigate a security problem before exploit details become widely available. The company said disclosures that put proof-of-concept code for unpatched vulnerabilities into attackers’ hands can expose customers to unnecessary risk.

The language in Microsoft’s original post prompted criticism from parts of the security research community, particularly over references to potential legal action. Microsoft later sought to clarify its position while continuing to advocate for coordinated disclosure.

ShieldBreak arrives just after Patch Tuesday

The timing is notable because ShieldBreak was disclosed immediately after Microsoft’s regularly scheduled August Patch Tuesday security updates. That means the newly published issue was not addressed in the month’s standard Windows patches.

For Windows users and administrators, the disclosure is another reason to keep systems fully updated even though the available updates do not specifically resolve ShieldBreak. Organisations can also reduce exposure to local privilege-escalation attacks by limiting users’ ability to execute untrusted software and applying least-privilege policies.

The immediate question is whether Microsoft’s investigation confirms the researcher’s findings and whether the company issues another Defender or Windows security update. Until then, ShieldBreak remains publicly documented while Microsoft evaluates the reported vulnerability.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.