Particle.news

ShieldBreak PoC Elevates Privileges via Microsoft Defender

Microsoft is investigating after researchers reproduced a public proof‑of‑concept that uses Defender’s cloud‑hydration scan to escalate an unprivileged app to SYSTEM.

Overview

  • The anonymous researcher known as Chaotic or Nightmare Eclipse published the ShieldBreak proof‑of‑concept on Wednesday and said it fully bypasses the July RoguePlanet fix.
  • Multiple independent analysts reproduced the PoC and confirmed it grants SYSTEM privileges only when Microsoft Defender is enabled.
  • Technical reviews show ShieldBreak manipulates Defender’s cloud‑hydration path and Cloud Filter API, uses a user‑mode callback to swap files into System32, and triggers a scheduled task to run attacker code as SYSTEM.
  • Microsoft acknowledged the report, said it is actively investigating and reiterated support for coordinated disclosure, and has not announced a vendor patch specific to ShieldBreak.
  • The release continues a months‑long run of public zero‑day disclosures by the same researcher, leaving system administrators to test updates, enable detections, or disable Defender where feasible to reduce short‑term exposure.