<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges-vuiyh7zjo" -->

---
title: New Microsoft Defender &#x27;ShieldBreak&#x27; zero-day grants...
description: A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldBreak, which bypasses the previously...
canonical: https://daily.dev/posts/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges-vuiyh7zjo
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New Microsoft Defender &#x27;ShieldBreak&#x27; zero-day grants SYSTEM privileges | daily.dev
og:description: A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldBreak, which bypasses the previously...
og:url: https://daily.dev/posts/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges-vuiyh7zjo
og:image: https://api.daily.dev/og/posts/VuIYH7ZjO.png
og:image:alt: New Microsoft Defender &#x27;ShieldBreak&#x27; zero-day grants SYSTEM privileges
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 2 min read · 0 upvotes · 0 comments

## Summary

A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldBreak, which bypasses the previously patched RoguePlanet vulnerability (CVE-2026-50656) to grant SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit requires Defender to be enabled and has a reported 100% success rate in testing, confirmed working by Will Dormann of Tharros. This is part of an ongoing dispute between Microsoft and the researcher, who has disclosed numerous other zero-days (LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, UnDefend) since April 2026 after Microsoft threatened legal action over the disclosures. Several of these flaws remain unpatched.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges>

## Questions this post answers

### What is the ShieldBreak Microsoft Defender zero-day exploit?

ShieldBreak is a proof-of-concept exploit released by researcher Nightmare Eclipse that bypasses Microsoft's patch for the RoguePlanet vulnerability (CVE-2026-50656), granting SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. It requires Microsoft Defender to be enabled and was reported to have a 100% success rate in testing on Windows 11 25H2 and Windows Server 2025.

_Security teams tracking Defender privilege escalation flaws can follow patch-bypass reports like this on daily.dev._

### Has Microsoft patched the RoguePlanet Defender vulnerability CVE-2026-50656 completely?

No, Microsoft's July patch for RoguePlanet (CVE-2026-50656) was incomplete. The ShieldBreak exploit, released by Nightmare Eclipse, demonstrates a full bypass of that patch, allowing attackers to still gain SYSTEM privileges on Windows systems that Microsoft considers fully patched.

_Admins verifying Defender patch coverage can track disclosures like this bypass on daily.dev._

### Why is Microsoft in a public dispute with the security researcher Nightmare Eclipse?

Microsoft threatened legal action against Nightmare Eclipse, warning against 'malicious activity causing real harm' to customers, after the researcher publicly disclosed a series of unpatched Windows zero-days including LegacyHive, RoguePlanet, BlueHammer, RedSun, and BitLocker flaws like YellowKey and GreenPlasma starting in April 2026. Cybersecurity experts viewed the warning as a direct threat rather than a standard coordinated disclosure response.

_Developers following disclosure disputes affecting Windows security can track the fallout on daily.dev._

## Similar posts on daily.dev

- [Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges](https://daily.dev/posts/microsoft-defender-rogueplanet-zero-day-grants-system-privileges-ldyxflycj) · BleepingComputer · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#windows](https://daily.dev/tags/windows), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges-vuiyh7zjo)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges","url":"https://daily.dev/posts/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges-vuiyh7zjo","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges-vuiyh7zjo"},"datePublished":"2026-08-12T10:17:24.148Z","dateModified":"2026-08-17T09:10:49.932Z","description":"A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldBreak, which bypasses the previously...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4a9af27f456b5a09e004ef5d9b6d2d94?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4a9af27f456b5a09e004ef5d9b6d2d94?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges-vuiyh7zjo","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,windows,zero-day","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges-vuiyh7zjo#faq","mainEntity":[{"@type":"Question","name":"What is the ShieldBreak Microsoft Defender zero-day exploit?","acceptedAnswer":{"@type":"Answer","text":"ShieldBreak is a proof-of-concept exploit released by researcher Nightmare Eclipse that bypasses Microsoft's patch for the RoguePlanet vulnerability (CVE-2026-50656), granting SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. It requires Microsoft Defender to be enabled and was reported to have a 100% success rate in testing on Windows 11 25H2 and Windows Server 2025. Security teams tracking Defender privilege escalation flaws can follow patch-bypass reports like this on daily.dev."}},{"@type":"Question","name":"Has Microsoft patched the RoguePlanet Defender vulnerability CVE-2026-50656 completely?","acceptedAnswer":{"@type":"Answer","text":"No, Microsoft's July patch for RoguePlanet (CVE-2026-50656) was incomplete. The ShieldBreak exploit, released by Nightmare Eclipse, demonstrates a full bypass of that patch, allowing attackers to still gain SYSTEM privileges on Windows systems that Microsoft considers fully patched. Admins verifying Defender patch coverage can track disclosures like this bypass on daily.dev."}},{"@type":"Question","name":"Why is Microsoft in a public dispute with the security researcher Nightmare Eclipse?","acceptedAnswer":{"@type":"Answer","text":"Microsoft threatened legal action against Nightmare Eclipse, warning against 'malicious activity causing real harm' to customers, after the researcher publicly disclosed a series of unpatched Windows zero-days including LegacyHive, RoguePlanet, BlueHammer, RedSun, and BitLocker flaws like YellowKey and GreenPlasma starting in April 2026. Cybersecurity experts viewed the warning as a direct threat rather than a standard coordinated disclosure response. Developers following disclosure disputes affecting Windows security can track the fallout on daily.dev."}}]}
```

