Threat Intelligence

ShieldBreak: The Microsoft Defender bypass every security team needs to understand

Jacob Dobson
Placeholder for Jacob DobsonJacob Dobson

Jacob Dobson , Head of Security Operations , Nomios UK&I

5 min. read
Placeholder for Adobe Stock 1095541179 Editorial Use OnlyAdobe Stock 1095541179 Editorial Use Only

Share

NOMIOS THREAT INTELLIGENCE

ShieldBreak: Microsoft Defender Patch Bypass Re-Opens SYSTEM-Level Privilege Escalation Path

Published: 13 August 2026

Updated: 13 August 2026

If Microsoft Defender Antivirus runs anywhere in your Windows estate, and for most enterprises it does, there's now a working, publicly available exploit that takes a standard user straight to full SYSTEM access. No patch exists. No CVE has been assigned. And it works against fully patched Windows 11 25H2 and Windows Server 2025.

That's not a hypothetical. It's the situation as of 13 August 2026, and it's one your security team needs visibility on now.

ShieldBreak: At a Glance:

 CategoryAssessment
 SeverityHigh
 Threat LevelMedium
 Exploit AvailabilityPublic working PoC
 In-the-Wild ExploitationNot observed
 Patch AvailableNo
 Microsoft AdvisoryNot issued
 Attack PrerequisitesLocal code execution
 Privilege GainedNT AUTHORITY\SYSTEM
 Affected ComponentMicrosoft Malware Protection Engine (mpengine.dll)

What's happening with ShieldBreak

A researcher who publishes under several aliases, most recently as Nightmare Eclipse, has released a working exploit called ShieldBreak. It's being described as a complete bypass of Microsoft's July 2026 fix for CVE-2026-50656, a Defender vulnerability known as RoguePlanet.

RoguePlanet targeted mpengine.dll, the privileged engine behind Defender's scanning and remediation, which runs under NT AUTHORITY\SYSTEM. The original flaw was a check-then-act race condition in how Defender handled files. Time the attack right, and you could redirect a trusted Defender operation towards attacker-controlled content and execute code as SYSTEM.

Microsoft patched RoguePlanet on 9 July 2026, via Malware Protection Engine version 1.1.26060.3008, and rated it "More Likely" to be exploited. According to the researcher, that fix closed one specific route to the vulnerable logic without removing the underlying condition. ShieldBreak reportedly reaches the same privileged code through a different path. Running the patched engine version is not, on its own, evidence that the underlying issue is resolved.

How ShieldBreak Works

Public technical write-ups describe an exploit chain that abuses Defender's own trusted, SYSTEM-level file handling. The reported technique combines:

  • Rogue cloud sync provider registration
  • Crafted placeholder files
  • Common Log File System (CLFS) log manipulation
  • Object Manager symbolic links
  • Defender scanning and remediation workflows

Put together, these coerce Defender into holding a privileged handle on a legitimate system file while an attacker swaps in a controlled object underneath it. Defender then processes that object with SYSTEM-level trust, and the attacker's code runs.

This overlaps significantly with the techniques seen in RoguePlanet, which used NTFS junctions, opportunistic locks and Windows Error Reporting scheduled tasks to similar effect. That overlap points to the same underlying privileged behaviour being reached through a new front door, rather than a distinct new vulnerability class.

Independent researcher Will Dormann has confirmed the exploit works as described, and that Defender must be enabled for it to succeed. Public reporting also confirms successful exploitation against Windows 11 25H2, including Insider Canary builds, and Windows Server 2025. Unlike RoguePlanet, which depended on winning a race condition, ShieldBreak is reported to work near-reliably, which makes it far more practical to weaponise.

Who is Exposed to ShieldBreak?

ShieldBreak is not remotely exploitable. It won't get an attacker into your environment. It becomes relevant only once someone already has local code execution as a standard user, through phishing, malware, or a compromised credential, and Defender is enabled on the host.

From there, the payoff is total. Successful exploitation hands an attacker:

  • Arbitrary code execution as NT AUTHORITY\SYSTEM
  • Local credential theft
  • The ability to disable or tamper with security controls
  • SYSTEM-level persistence
  • Access to machine account credentials
  • A route to lateral movement and full host compromise

The inclusion of Windows Server 2025 in the confirmed scope matters. That puts domain controllers, admin jump hosts, VDI platforms and session hosts firmly in play, not just end-user devices.

Why ShieldBreak Needs Attention Now

A handful of things push ShieldBreak up the priority list:

  • Microsoft Defender is a prerequisite for exploitation and is enabled by default across most modern Windows deployments.
  • The exploit code is public and weaponised.
  • It's been independently validated, not just claimed.
  • Microsoft has no fix, advisory, or CVE for it yet.
  • Defender is the default AV on most enterprise Windows estates.
  • It was published less than 24 hours after Microsoft's August Patch Tuesday, giving attackers a head start before the next update cycle.

There's also the researcher's track record. Their three previous disclosures, BlueHammer, RedSun and UnDefend, were all later observed in real-world attacks and added to CISA's Known Exploited Vulnerabilities catalogue. No in-the-wild exploitation of ShieldBreak has been confirmed yet, but public, independently verified privilege escalation exploits with this kind of platform coverage rarely stay theoretical for long.

What to do about ShieldBreak

Until Microsoft ships a fix, there are practical steps worth taking:

  • Watch for the fix. Monitor Microsoft Security Response Centre for an advisory, CVE assignment or updated Malware Protection Engine build.
  • Tighten local execution. Restrict unnecessary local code execution through application control policies where you can.
  • Review privileged credential exposure on endpoints and servers, particularly anywhere Server 2025 is in scope.
  • Increase telemetry review around CLFS abuse, symbolic link creation, NTFS junction manipulation, cloud sync provider registration, and unexpected SYSTEM-level process creation.
  • Flag unusual privilege escalation activity for investigation rather than automatic dismissal.

How Nomios is Responding to ShieldBreak

Our Security Operations and Threat Intelligence teams are actively tracking ShieldBreak and assessing its impact across managed environments. For Nomios Managed SOC customers, that means monitoring for indicators of exploitation, tracking Microsoft's advisories and engine updates, feeding relevant intelligence into ongoing detection, and running customer-specific threat hunting and exposure assessments where that's part of the contracted service.

If you're a Nomios customer and want to understand your exposure, speak to your Service Delivery Manager or Account Manager about what's available within your service scope.

ShieldBreak: Summary

ShieldBreak bypasses Microsoft's July patch for RoguePlanet (CVE-2026-50656), taking a standard user to full SYSTEM access on fully patched Windows 11 25H2 and Windows Server 2025, with no CVE, advisory or fix currently available. It won't get an attacker through the door on its own, since it needs local code execution first, but once they're in, it provides a reliable route to complete control of the affected host and may facilitate wider compromise depending on the role of the system and any credentials available to the attacker. The researcher behind it has a track record of disclosures that later turned up in real attacks, so this is worth treating as a when, not an if, until Microsoft closes it off.

Connect with us

Get in touch with our industry experts

Combining deep industry expertise, advanced security and network capabilities and human-led design methodologies to enable clients to act with speed and confidence.

Talk to an expert
Updates

More updates