ShieldBreak turns Defender into a way up
A privilege escalation flaw disclosed without notice, with a working exploit and no patch yet.
SeverityHigh
2 minThreat Intelligence
A vulnerability in Microsoft Defender, tracked as CVE-2026-69414 and named ShieldBreak, lets a local attacker with limited permissions escalate to SYSTEM. It affects Windows 10, Windows 11 in version 25h2 and the Canary channel, Windows Server 2025 and the corresponding server editions.
The condition that makes it work is worth stating plainly: Defender has to be enabled. The security product is the path.
Disclosed without warning
A researcher using the handle Nightmare Eclipse published the flaw without notifying Microsoft first, and released a proof-of-concept reported to succeed every time in lab testing. Microsoft says it is working to provide a high quality security update; as of 17 August there is no patch.
There is no reported evidence of exploitation by threat actors so far. That gap tends to be short when a reliable exploit is already public.
The detail defenders should weigh most heavily is lineage. ShieldBreak is reported to bypass the fix for RoguePlanet, CVE-2026-50656, which Microsoft addressed in July. A patched issue returning through a different route in the same component suggests the underlying design, not the specific bug, is what allowed it.
Retold from BleepingComputer. This is a summary in our own words; follow the link for the original reporting.