Security Researcher Publishes New Windows Zero-Day Despite Microsoft's Legal Threats

A security researcher has publicly disclosed a new vulnerability in the latest versions of Windows that could allow attackers to gain system-wide access to a user's device and data—despite facing legal threats from Microsoft weeks earlier over the release of previously undisclosed software flaws. The newly discovered bug, dubbed ShieldBreak, is the latest in a series of disclosures by the researcher known as Nightmare Eclipse, who has recently published details of several vulnerabilities affecting Microsoft products, including Windows. According to Nightmare Eclipse's technical write-up, ShieldBreak exploits a flaw in Windows Defender, the built-in anti-malware and security engine. A successful attack enables an attacker to escalate privileges from a low-level user to full administrative access—essentially taking complete control of the device and its data. The proof-of-concept exploit is distributed as a Windows application, requiring the user to run it locally to trigger the vulnerability. The researcher confirmed that the bug affects Windows 10, Windows 11 (including the latest 25H2 update), and Windows Server 2025. Independent security researcher Will Dormann verified the exploit's functionality and noted that Windows Defender must be enabled for the attack to succeed. ShieldBreak builds on an earlier exploit by Nightmare Eclipse, known as RoguePlanet. Microsoft had released a patch for RoguePlanet (tracked as CVE-2026-50656), but the researcher claims that the fix was incomplete, and the new exploit represents a full bypass of the earlier patch. As of this writing, Microsoft has not released a patch for ShieldBreak. A company spokesperson did not respond immediately to TechCrunch's request for comment. Because Microsoft was not given advance notice before the disclosure, the flaw is considered a zero-day vulnerability. This release is the latest escalation in an ongoing conflict between Nightmare Eclipse and Microsoft over how the company handles vulnerability reports. In a series of blog posts, the researcher accused Microsoft of mistreating them and failing to adequately address their findings, implying that public disclosure was the only remaining option. Previously, Nightmare Eclipse released several other Windows flaws that were later exploited in real-world attacks against organizations. In May, Microsoft published a blog post warning that it would pursue legal action against security researchers who disclosed zero-day vulnerabilities outside the company's coordinated disclosure policies. The post drew sharp criticism from the security community, with many researchers citing similar negative experiences with Microsoft's reporting processes. While Microsoft later attempted to soften its stance in a social media post, the original blog post remains online and unchanged. The continued public disclosure of these vulnerabilities raises significant questions about the effectiveness of Microsoft's patching processes and its relationship with the security research community in 2026.

via TechCrunch

Related