Microsoft Defender ShieldBreak Zero Day Demonstrates RoguePlanet Patch Bypass

Published:

Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare Eclipse, has released a proof of concept for a newly disclosed Microsoft zero day named ShieldBreak. According to the researcher, the vulnerability affects Microsoft Defender for Windows and serves as a patch bypass for the previously disclosed RoguePlanet vulnerability, tracked as CVE 2026 50656 with a CVSS score of 7.8. The new proof of concept claims that systems running the latest versions of Windows 11 25H2 and Windows Server 2025 remain vulnerable despite Microsoft’s earlier security update. ShieldBreak is said to enable attackers to obtain SYSTEM level privileges, allowing them to execute arbitrary code or perform unauthorized actions with the highest level of access on affected systems.

RoguePlanet was first disclosed by Chaotic Eclipse in June 2026 as a race condition vulnerability within the Microsoft Malware Protection Engine, identified as mpengine.dll. Successful exploitation could allow attackers to spawn a shell with SYSTEM privileges, significantly increasing the impact of a compromise. Microsoft released a patch for the issue nearly a month after its disclosure, classifying it as a privilege escalation vulnerability. However, shortly after the security update became available, the researcher reported that Microsoft’s defense in depth changes introduced another issue that could cause Microsoft Defender to leak eight bytes of data when attempting to open a file under specific conditions on Windows 11 25H2 and Windows Server 2025. Microsoft acknowledged the report at the time and stated that it was investigating the findings.

The newly released ShieldBreak proof of concept is described by the researcher as a complete bypass of the RoguePlanet patch, with claims that Microsoft did not fully address the underlying vulnerability. According to the published research, the proof of concept achieved a reported 100 percent success rate during testing on the latest Windows 11 25H2 Canary Channel builds and Windows Server 2025. Although Windows 10 and corresponding server editions are not currently supported by the proof of concept, the researcher stated that those operating systems are also vulnerable to ShieldBreak. Microsoft has not yet publicly responded to the latest claims, although media outlets have contacted the company for comment regarding the reported bypass and the effectiveness of its previous security update.

The disclosure comes shortly after Microsoft released security updates addressing 421 vulnerabilities across its products, including 236 affecting Windows. Among those fixes was CVE 2026 62832, a Windows User Profile Service privilege escalation vulnerability disclosed by Chaotic Eclipse under the name LegacyHive. Microsoft explained that the flaw involves improper link resolution before file access, enabling an authenticated attacker with credentials for another local account to load another user’s registry hive, potentially gaining administrator privileges without requiring user interaction. The August security updates also addressed an actively exploited zero day in the Windows Ancillary Function Driver for WinSock, tracked as CVE 2026 68820, which grants SYSTEM privileges, as well as a publicly disclosed Windows Container Isolation FS Filter Driver tampering vulnerability identified as CVE 2026 72971. Following Microsoft’s release of the patches, U.S. Cybersecurity and Infrastructure Security Agency added CVE 2026 68820 to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply the available security updates by August 25, 2026.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img