Zero Day Room
Live
Vulnerabilities

Microsoft Defender Patch Bypass Exploit Claims SYSTEM Access

A security researcher has released a proof-of-concept exploit for a Microsoft zero-day vulnerability, claiming it can bypass a previously released patch and grant an attacker SYSTEM-level privileges.

Microsoft Defender Patch Bypass Exploit Claims SYSTEM Access

Security researchers have discovered a new Microsoft zero-day vulnerability, dubbed **ShieldBreak**, which allegedly allows attackers to bypass a previously released patch and gain SYSTEM-level privileges. The vulnerability, rooted in Microsoft Defender for Windows, is a proof-of-concept (PoC) exploit developed by security researcher Chaotic Eclipse. The exploit claims to bypass the patch for CVE-2026-50656, also known as RoguePlanet, which was previously described as a race condition that could grant an attacker the ability to spawn a shell with SYSTEM-level privileges. Chaotic Eclipse claims that the "defense-in-depth updates" introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025. Microsoft has acknowledged the report and is investigating the claims. The ShieldBreak exploit is said to have a 100% success rate on the latest version of Windows 11 25H2 (+Canary channel) and Windows Server 2025. However, it is not currently supported on Windows 10 (and respective server editions), although the researcher claims that these systems are also vulnerable to the exploit. Microsoft has released a statement confirming that they are aware of the reported vulnerability and are actively investigating its validity and potential applicability. The company is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Security researcher Kevin Beaumont has validated the exploit, stating that it works differently from RoguePlanet. Beaumont explained that RoguePlanet was a filesystem race condition vulnerability that uses virtual disks and NT native file manipulation to trick the quarantine process into overwriting system files. In contrast, ShieldBreak uses a user-mode callback hook to change file contents during a Defender cloud-hydration scan via the Cloud Filter API. Will Dormann, principal vulnerability analyst at Tharros, has also validated ShieldBreak, stating that Defender needs to be enabled for the exploit to work. Dormann explained the sequence of actions required to exploit the vulnerability, which involves planting an EICAR file, using Object Manager symlinks to control Defender's scan path to system32, and leveraging CLFS to swap the identity file and hydration data to C:\Windows\system32\phoneinfo.dll. The development comes as Microsoft has shipped patches for 421 security flaws, including 236 flaws in Windows. One of the patches involves CVE-2026-62832, a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name LegacyHive. Microsoft has also remediated an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (CVE-2026-72971, CVSS score: 5.5). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-68820 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by August 25, 2026.

Related coverage

More from Vulnerabilities