Microsoft Windows Zero-Day ShieldBreak Enables Full Device Takeover
Microsoft faces ShieldBreak, a Windows zero-day exposing Windows 10, Windows 11 and Server 2025 to full device takeover, with no patch available from Microsoft.
Summary
On August 12, 2026, security researcher Nightmare Eclipse published ShieldBreak, a Windows Defender flaw allowing attackers to escalate low-level user permissions into system-wide access to a device and its data. The proof-of-concept is a Windows app that users must run. Nightmare Eclipse said it affects Windows 10, Windows 11, including version 25H2, and Windows Server 2025. Researcher Will Dormann verified the exploit and confirmed Windows Defender must be enabled. Microsoft had not released a patch or immediately commented to TechCrunch, making ShieldBreak a zero-day because it was disclosed without advance time for remediation.
Nightmare Eclipse said ShieldBreak fully bypasses Microsoft’s patch for their earlier RoguePlanet exploit. The researcher has accused Microsoft of mishandling bug reports and previously released Windows flaws later used in real attacks against organizations. In May 2026, Microsoft threatened legal action against researchers disclosing zero-days outside its policies, drawing security-community criticism before the company withdrew the comments on social media, although its original blog post remains unchanged. ShieldBreak appeared one day after Patch Tuesday, the second consecutive month Microsoft issued roughly 500 fixes, a volume attributed to growing AI-assisted flaw discovery.
Positives
- Will Dormann independently verified ShieldBreak and identified Windows Defender as a requirement for exploitation.
- ShieldBreak requires a user to run the proof-of-concept Windows app, limiting fully automatic exploitation through this published method.
- Microsoft previously patched RoguePlanet, the earlier exploit on which Nightmare Eclipse says ShieldBreak builds.
- Roughly 500 fixes arrived on Patch Tuesday for a second consecutive month as Microsoft expanded AI-assisted vulnerability discovery.
- Microsoft withdrew its May 2026 legal-threat comments on social media after criticism from the security community.
Risks & concerns
- ShieldBreak gives attackers system-wide access to affected devices and data after starting with low-level user permissions.
- Windows 10, Windows 11 version 25H2 and Windows Server 2025 are vulnerable, according to Nightmare Eclipse.
- Microsoft had no ShieldBreak patch available when the vulnerability and proof-of-concept exploit were publicly released.
- ShieldBreak allegedly fully bypasses Microsoft’s earlier RoguePlanet patch, suggesting that fix was insufficient.
- Nightmare Eclipse’s previously disclosed Windows flaws were later exploited in real-world attacks against organizations.
- Microsoft’s unchanged May 2026 blog post still threatens legal action over zero-day disclosures outside company policies.