Get App
Download App Scanner
Scan to Download
Advertisement

New Microsoft Defender Bug Could Give Hackers Full System Access

A newly disclosed Microsoft Defender vulnerability, dubbed SheildBreak, could allow attackers to gain full system access. The flaw was published shortly after Microsoft's latest security update.

New Microsoft Defender Bug Could Give Hackers Full System Access
Security researcher Will Dormann independently verified the reported behaviour and said Microsoft Defender needs to be enabled for the exploit to work.
Unsplash

A security researcher has released details of a new windows vulnerability that could allow hackers to gain full control of a computer, shortly after Microsoft issued its latest monthly security updates. The vulnerability, called ShieldBreak, affects Microsoft Defender, the security software built into windows.

Researcher Nghtmare Eclipse has published a proof-of-concept exploit showing how the flaw can potentially be used to escalate privileges from a low-level account to system-level access, giving an attacker extensive control over the device and its data, according to security reports.

The exploit has reportedly been tested on Windows 11 version 25H2 and windows server 2025. Nightmare Eclipse also said Windows 10 and other supported server editions are vulnerable as well, although the published proof-of-concept was not tested on those versions. Security researcher Will Dormann independently verified the reported behaviour and said Microsoft Defender needs to be enabled for the exploit to work.

SheildBreak is particularly significant because it is described as a bypass of Microsoft's earlier fix for another Microsoft Defender vulnerability, known as RoguePlanet, tracked as CVE-2026-50656 in its July security updates. Nightmare Eclipse claims the new exploit can circumvent that patch. Microsoft has not yet released a specific security update for SheildBreak.

The company did not immediately comment on the newly disclosed vulnerability when contacted by TechCrunch.

The disclosure comes amid a dispute between Microsoft and Nightmare Eclipse over the handling of security vulnerabilities. In May, Microsoft warned that researchers could face legal action if they publicly disclosed flaws outside its vulnerability disclosure process. The company later softened its position following criticism from security community. SheildBreak was disclosed shortly after Microsoft's August 11 patch release. Microsoft said its latest security update adressed vulnerabilities across supported products, with security researchers counting hundreds of fixes, including 398CVEs in one widely cited tally.

A zero-day is a security vulnerability that is publicly disclosed before the software maker has released a fix, potentially giving attackers an opportunity to exploit affected systems.

Also Read | Microsoft Unveils $20.5-Billion AI-Backed Cloud Region In Hyderabad
 

Essential Business Intelligence, Sharp Market Insights, Practical Personal Finance Advice, Daily Fuel, Gold and Silver Prices and Latest Stories — On NDTV Profit.

Newsletters

Update Email
to get newsletters straight to your inbox
⚠️ Add your Email ID to receive Newsletters
Note: You will be signed up automatically after adding email

News for You

Set as Trusted Source
on Google Search
Add NDTV Profit As Google Preferred Source
Listen to the latest songs, only on JioSaavn.com