Particle.news

Researcher Publishes ShieldBreak PoC That Bypasses Microsoft’s RoguePlanet Fix

Independent analysts confirmed the exploit can grant SYSTEM access on modern Windows machines and Microsoft has not issued a ShieldBreak patch.

Overview

  • On Wednesday the researcher known as Chaotic Eclipse released a proof-of-concept called ShieldBreak that they say fully bypasses the July fix for CVE-2026-50656 (RoguePlanet) and grants SYSTEM-level privileges on affected machines.
  • Multiple independent analysts tested the PoC and confirmed it works on Windows 11 25H2 and Windows Server 2025 and said Windows 10 is likely vulnerable as well.
  • Researchers report ShieldBreak requires Microsoft Defender to be active and abuses Defender’s scanning behavior by using a user-mode callback during a CFAPI cloud-hydration scan to replace a system DLL and execute code as SYSTEM.
  • Microsoft had not published a ShieldBreak-specific patch or substantive public comment at the time of reporting and security teams have suggested temporary mitigations such as disabling Defender or applying community detection rules.
  • The release extends a months-long conflict between the researcher and Microsoft over out-of-policy zero-day disclosures and highlights a gap between published PoCs, independent verification, and vendor-issued fixes that system administrators must now manage.