ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
Key Points:
- Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) called ShieldBreak, which bypasses the patch for Microsoft Defender zero-day vulnerability CVE-2026-50656 (RoguePlanet), a race condition that allows privilege escalation to SYSTEM-level access.
- RoguePlanet was disclosed in June 2026 but patched by Microsoft nearly a month later; however, Chaotic Eclipse claims the patch is ineffective, with ShieldBreak achieving a 100% success rate on Windows 11 25H2 and Windows Server 2025.
- Microsoft recently addressed 421 security flaws, including CVE-2026-62832 (LegacyHive), a privilege escalation vulnerability in the Windows User Profile Service disclosed by Chaotic Eclipse, and CVE-2026-68820, an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock.
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the actively exploited CVE-2026-68820 vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches by August 25, 2026.
- Microsoft is investigating additional issues reported by Chaotic Eclipse related to data leakage in Defender following the RoguePlanet patch, highlighting ongoing security challenges despite recent updates.