Skip to content
Tech News
← Back to articles

Microsoft's nemesis drops new zero-day privilege escalation vulnerability — attack grants system-level privileges, but it could already be patched

read original more articles
Why This Matters

The discovery of the ShieldBreak zero-day vulnerability highlights ongoing challenges in securing Windows systems against sophisticated exploits. While Microsoft has issued patches and detection tools, the existence of unpatched or undiscovered vulnerabilities underscores the importance of vigilant security practices for both industry professionals and consumers.

Key Takeaways

Prolific hacker and Microsoft nemesis 'Nightmare Eclipse' has just published ShieldBreak, yet another Windows zero-day vulnerability that ought to get you SYSTEM-level privileges just by running some code as a regular user. Although Eclipse has generally kept ahead of Microsoft, it seems the company may be catching up, as our own quick testing found this exploit is already detected by Defender and might even be patched as of last Tuesday.

As described by the author, ShieldBreak is essentially a continuation of the previously reported RoguePlanet vulnerability in Windows Defender's subsystems. Eclipse claims that Microsoft failed to properly patch RoguePlanet, and that ShieldBreak in theory bypasses the recently added protection.

The proof-of-concept code for the new exploit is supposed to bring up a super-elevated command prompt with SYSTEM privileges (higher than Administrator). The author claims the vulnerability is present in the "latest" versions of Windows 11, Windows Server 2025, and Windows 10, though the proof-of-concept is limited to the former two operating systems.

Latest Videos From Tom's Hardware Watch full video here:

Although researchers like Kevin Beaumont and Will Dormann say they've successfully reproduced the exploit, our informal testing in a Windows 11 virtual machine didn't yield any results. Said VM was just updated yesterday with the latest Windows 11 patches and currently sits at version 10.0.26200.9168. Given that Microsoft just published a giga-patch last Tuesday, there's a solid chance it plugged whichever hole ShieldBreak was getting through.

The sample screenshot in the ShieldBreak repository shows the exploit working under version 10.0.26100.33296, lending some credence to this theory. A sample size of one does not research make, so we advise caution and remind everyone to run their own testing before assuming the bug has truly been fixed.

Microsoft appears to have already published a Defender detection for it. We found it when double-checking our results, with just a 20-minute window between both tests, as shown in the screenshot below.

(Image credit: Future)

Even if the issue is fixed, not every user updates their machines as soon as patches are available, and perhaps more importantly, corporations tend to hold back on patches until they know they don't bring in any new issues. That means that a good portion of the world's machines may still be vulnerable to ShieldBreak.

Stay On the Cutting Edge: Get the Tom's Hardware Newsletter Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors

... continue reading