Security News New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers

Anyone who goes against the grain. Everyone knows they are communists, anarchists and ANTIFA! :LOL:
Not to get into politics but the right has shifted and now the left has shifted aligning it self with communism and socialism. Ying and Yang I guess.
 
Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability

The prolific and controversial security researcher known as Nightmare-Eclipse (also tracked under the alias Chaotic Eclipse) has released a ninth Windows zero-day exploit called ShieldBreak, and this time the target is Microsoft’s own fix.

ShieldBreak demonstrates a complete bypass of the patch Microsoft shipped for RoguePlanet, the Windows Defender elevation-of-privilege flaw tracked as CVE-2026-50656, proving that the underlying weakness in the Microsoft Malware Protection Engine was never fully closed.

RoguePlanet was originally disclosed as a race condition in mpengine.dll, the core scanning engine behind Windows Defender, that let a local attacker win a narrow check-then-act timing window during a file scan and redirect it into a command shell running as NT AUTHORITY\SYSTEM.

Microsoft eventually acknowledged the bug, rated it “Exploitation More Likely” with a CVSS score of 7.8, and remediated it in Malware Protection Engine version 1.1.26060.3008 during its July 2026 patch cycle.

 
Microsoft working on Defender patch for ShieldBreak zero-day

Nightmare Eclipse described ShieldBreak as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June, and shared a ShieldBreak proof-of-concept (PoC) exploit that local attackers with limited permissions can use to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.

 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top