New ShieldBreak Exploit Gives Limited Windows Accounts Full Control


TL;DR

  • Limited Test: A new Windows exploit called ShieldBreak allows a limited local Windows account reach SYSTEM, the machine’s highest access privilege.
  • Published and Reproduced: Cybersecurity researcher Nightmare Eclipse published ShieldBreak; independent researcher Will Dormann later reproduced the underlying privilege jump.
  • Scope Limits: Nightmare Eclipse says ShieldBreak was tested on Windows 11 25H2, prerelease Windows Insider Canary builds, and Windows Server 2025.
  • Microsoft Response: As of August 13, 2026, Microsoft was investigating but had not confirmed ShieldBreak, listed affected versions, or published a specific fix or workaround.
  • Update Check: Keep Defender updated through Windows’ normal channels; administrators should confirm managed devices receive its antivirus engine, protection platform, and security intelligence updates because no ShieldBreak-specific fix is confirmed.

The ShieldBreak exploit starts after code is already running under a limited Windows account, then seeks SYSTEM, the operating system’s highest local privilege. Nightmare Eclipse says the exploit bypasses Microsoft’s July engine update for RoguePlanet, an earlier Defender flaw. 

From a Limited Account to SYSTEM

Nightmare Eclipse published ShieldBreak on August 11. Later that day, independent security researcher Will Dormann reproduced the result: a limited user reached SYSTEM, and Defender had to be enabled for the exploit to work in his test.

An attacker would therefore need a way to run code in a limited account before ShieldBreak could raise privileges. Required local code execution makes ShieldBreak different from an unauthenticated network attack, but reaching SYSTEM would still turn a modest foothold into control of the machine. 

What the Limited Test Establishes

Nightmare Eclipse lists Windows 11 25H2, prerelease Windows Insider Canary builds, and Windows Server 2025 as tested targets. The researcher also claims Windows 10 and corresponding Windows Server releases are affected, although the published exploit demonstration does not cover those targets.

Microsoft was investigating the report as of August 13, but had not confirmed the vulnerability. It had not published a ShieldBreak advisory, affected-version table, fix, or supported workaround. The exploit code was public, while malicious use in attacks remained unknown.