A researcher known as Nightmare Eclipse (also going by Chaotic Eclipse, INFINITE NIGHTMARE, and MSNightmare) has published a proof-of-concept exploit named ShieldBreak that bypasses Microsoft’s patch for a previously disclosed Microsoft Defender privilege escalation vulnerability.
The exploit targets CVE-2026-50656 (CVSS 7.8), known as RoguePlanet, which Microsoft patched in July after it was disclosed in June. According to the researcher, ShieldBreak demonstrates a full bypass of that patch and can be used to gain SYSTEM privileges on fully updated Windows 10, Windows 11, and Windows Server systems, including Windows 11 25H2 and the Canary channel, as well as Windows Server 2025. The PoC reportedly achieves a 100% success rate in testing, and while Windows 10 and its server equivalents are not officially supported by the tooling, they remain vulnerable.
Security researcher Kevin Beaumont, who published detection queries for Microsoft Defender for Endpoint to help identify ShieldBreak activity, noted that the two exploits work through different mechanisms. RoguePlanet relied on a filesystem race condition using virtual disks and NT native file manipulation to trick the quarantine process into overwriting system files. ShieldBreak instead uses a user-mode callback hook to alter file contents during a Defender cloud-hydration scan via the Cloud Filter API (cfapi).
Will Dormann, principal vulnerability analyst at Tharros, confirmed the exploit functions as described, noting that Microsoft Defender must be enabled for the privilege escalation to succeed.
Part of an ongoing dispute
ShieldBreak is the latest release in a running conflict between Microsoft and Nightmare Eclipse over the company’s vulnerability disclosure and bug bounty practices. Microsoft has previously warned of possible legal action against individuals engaging in activity it characterizes as causing real harm to customers, a stance some security experts interpreted as a direct threat against the researcher.
Since April 2026, Nightmare Eclipse has disclosed a string of zero-days affecting Microsoft Defender, BitLocker, and other Windows components, including LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. Microsoft has patched YellowKey, GreenPlasma, and MiniPlasma as part of the June 2026 Patch Tuesday and fixed RoguePlanet in July, but the remaining vulnerabilities, now including the ShieldBreak bypass, are still unpatched.
Microsoft has been contacted for comment on ShieldBreak but had not issued a statement at the time of reporting.
