TL;DR
- Limited Test: A new Windows exploit called ShieldBreak allows a limited local Windows account reach SYSTEM, the machine’s highest access privilege.
- Published and Reproduced: Cybersecurity researcher Nightmare Eclipse published ShieldBreak; independent researcher Will Dormann later reproduced the underlying privilege jump.
- Scope Limits: Nightmare Eclipse says ShieldBreak was tested on Windows 11 25H2, prerelease Windows Insider Canary builds, and Windows Server 2025.
- Microsoft Response: As of August 13, 2026, Microsoft was investigating but had not confirmed ShieldBreak, listed affected versions, or published a specific fix or workaround.
- Update Check: Keep Defender updated through Windows’ normal channels; administrators should confirm managed devices receive its antivirus engine, protection platform, and security intelligence updates because no ShieldBreak-specific fix is confirmed.
The ShieldBreak exploit starts after code is already running under a limited Windows account, then seeks SYSTEM, the operating system’s highest local privilege. Nightmare Eclipse says the exploit bypasses Microsoft’s July engine update for RoguePlanet, an earlier Defender flaw.
From a Limited Account to SYSTEM
Nightmare Eclipse published ShieldBreak on August 11. Later that day, independent security researcher Will Dormann reproduced the result: a limited user reached SYSTEM, and Defender had to be enabled for the exploit to work in his test.
An attacker would therefore need a way to run code in a limited account before ShieldBreak could raise privileges. Required local code execution makes ShieldBreak different from an unauthenticated network attack, but reaching SYSTEM would still turn a modest foothold into control of the machine.
What the Limited Test Establishes
Nightmare Eclipse lists Windows 11 25H2, prerelease Windows Insider Canary builds, and Windows Server 2025 as tested targets. The researcher also claims Windows 10 and corresponding Windows Server releases are affected, although the published exploit demonstration does not cover those targets.
Microsoft was investigating the report as of August 13, but had not confirmed the vulnerability. It had not published a ShieldBreak advisory, affected-version table, fix, or supported workaround. The exploit code was public, while malicious use in attacks remained unknown.
Dormann did not name the Windows build or Defender engine version he used. His brief Defender-enabled result supports ShieldBreak’s feasibility, but it does not confirm the author’s full product list or a uniform success rate across those systems. The undisclosed engine version also means his result cannot show whether ShieldBreak works on systems that received Microsoft’s July fix.
Why the July Fix Matters
Nightmare Eclipse says ShieldBreak defeats Microsoft’s earlier repair for RoguePlanet, a Defender flaw tracked as CVE-2026-50656. Microsoft has not confirmed whether ShieldBreak bypasses that repair or how the two conditions relate.
Microsoft’s RoguePlanet advisory says an authenticated attacker could gain SYSTEM privileges through Defender and identifies Malware Protection Engine 1.1.26060.3008 as the first fixed release on July 8.
What Windows Users Should Do
Microsoft has not published a ShieldBreak-specific fix, so Windows users should keep Defender updated through Windows’ normal channels. Administrators should confirm that managed devices receive its antivirus engine, protection platform, and security intelligence updates, then monitor Microsoft’s guidance for affected versions and a fixed release.
Routine updates and delivery checks maintain baseline protection and prepare devices to receive any future fix, but they are not a ShieldBreak-specific remedy.


