hacker-news · Crawled Aug 12, 2026

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

Read original article ↗

AI Summary

Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit called ShieldBreak, which demonstrates a full patch bypass for CVE-2026-50656 (RoguePlanet), a previously patched Microsoft Defender for Windows vulnerability. The original flaw was a race condition in the Microsoft Malware Protection Engine (mpengine.dll) that could allow privilege escalation to SYSTEM-level access. ShieldBreak allegedly achieves 100% success in bypassing the fix on Windows 11 25H2 and Windows Server 2025, indicating the patch was incomplete. Microsoft is investigating follow-up reports of data leakage during file operations, and the vulnerability remains exploitable despite prior remediation efforts.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.