Microsoft Defender zero-day exploit allows privilege escalation on Windows

A researcher has released ShieldBreak, a zero-day exploit for Microsoft Defender that grants SYSTEM privileges on fully patched Windows systems, according to BleepingComputer.

A security researcher known as Nightmare Eclipse has released a zero-day exploit for Microsoft Defender called ShieldBreak, according to BleepingComputer. The vulnerability allows attackers to gain SYSTEM privileges on Windows 10, Windows 11, and Windows Server systems, even when fully patched. ShieldBreak works by using a user-mode callback hook to alter file contents during a Defender cloud-hydration scan.

The exploit was released after Microsoft's August 2026 security updates, and Nightmare Eclipse claims it bypasses the earlier RoguePlanet vulnerability that Microsoft patched in July. The researcher states the ShieldBreak proof of concept achieved a 100 percent success rate on Windows 11 and Windows Server 2025. Security experts confirmed the exploit works when Microsoft Defender is enabled, but Microsoft has not yet released a patch.