Overview
- On Wednesday the researcher known as Chaotic Eclipse released a proof-of-concept called ShieldBreak that they say fully bypasses the July fix for CVE-2026-50656 (RoguePlanet) and grants SYSTEM-level privileges on affected machines.
- Multiple independent analysts tested the PoC and confirmed it works on Windows 11 25H2 and Windows Server 2025 and said Windows 10 is likely vulnerable as well.
- Researchers report ShieldBreak requires Microsoft Defender to be active and abuses Defender’s scanning behavior by using a user-mode callback during a CFAPI cloud-hydration scan to replace a system DLL and execute code as SYSTEM.
- Microsoft had not published a ShieldBreak-specific patch or substantive public comment at the time of reporting and security teams have suggested temporary mitigations such as disabling Defender or applying community detection rules.
- The release extends a months-long conflict between the researcher and Microsoft over out-of-policy zero-day disclosures and highlights a gap between published PoCs, independent verification, and vendor-issued fixes that system administrators must now manage.