← All News

New Windows Defender Zero-Day Can Give Attackers System Control

By CU Today Staff —

NEW YORK--A security researcher who has repeatedly uncovered flaws in Microsoft products has disclosed another Windows zero-day, this time a privilege-escalation vulnerability in Windows Defender that can give a low-privileged attacker system-level control, according to BankInfoSecurity.

The researcher, who uses the handle Nightmare Eclipse, dubbed the vulnerability “ShieldBreak,” and Microsoft told BankInfoSecurity parent ISMG it is investigating the claims.

BankInfoSecurity reported the exploit abuses Windows Defender’s privileged scanning capabilities while files are being processed through the Cloud Filter API. Security researchers Kevin Beaumont and CERT Coordination Center vulnerability analyst Will Dormann independently reproduced the proof of concept. Dormann found the technique can place an attacker-controlled phoneinfo.dll file in the Windows System32 directory and then use a highly privileged Windows Error Reporting task to execute the malicious code with system privileges.

According to BankInfoSecurity, Nightmare Eclipse described ShieldBreak as a bypass of Microsoft’s fix for the previously disclosed RoguePlanet vulnerability, CVE-2026-50656, although Dormann said the techniques appear substantially different. Microsoft said it emphasizes coordinated vulnerability disclosure and intends to patch affected products as soon as possible, while Eclipse has publicly criticized the company’s handling of vulnerability researchers and claimed to have identified additional weaknesses in Windows security mitigations.

The disclosure comes as Microsoft confronts a surge in reported vulnerabilities. BankInfoSecurity reported Microsoft issued fixes for 419 vulnerabilities in its August Patch Tuesday release, following 206 patches in June and a record 622 in July. Rapid7 Principal Engineer Adam Barnett told ISMG the growing vulnerability volume could prove an even larger challenge than Microsoft’s dispute with Eclipse, adding that Microsoft’s interests are best served by maintaining productive relationships with security researchers.

Originally reported by CU Today.