Particle.news

ShieldBreak PoC Bypasses Microsoft RoguePlanet Patch and Gains SYSTEM Access

The public exploit raises urgent exposure for Defender-enabled systems by showing the July fix can be bypassed and increases pressure for a new Microsoft update.

Overview

  • A researcher using the name Chaotic Eclipse released a proof-of-concept called ShieldBreak that they say fully bypasses Microsoft’s July patch for CVE-2026-50656, a Defender privilege-escalation flaw.
  • The PoC, published Wednesday, August 12, 2026, was tested by the researcher on Windows 11 25H2 and Windows Server 2025 with a claimed 100% success rate and is said to also affect Windows 10.
  • Independent analyst Will Dormann of Tharros confirmed the exploit works and said escalation to SYSTEM requires Microsoft Defender to be enabled on the target machine.
  • Microsoft has been contacted about ShieldBreak but has not published a specific patch addressing the new PoC, leaving defenders to weigh configuration changes and other mitigations.
  • The release deepens a public dispute over disclosure practices after the researcher’s prior Defender and Windows PoCs and comes as Microsoft issued large August updates while CISA added a separate actively exploited Windows zero-day to its KEV list.