CVE-2026-50656
CVSS 7.8 HIGH: microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender… EPSS 0.4% (28th percentile). Microsoft patch: Release Notes.
Vulnerabilities & Exploits · Zero-Day Exploit
Nightmare Eclipse published ShieldBreak on August 2026 Patch Tuesday, a proof-of-concept exploit for Microsoft Defender that can give a normal user SYSTEM privileges on current Windows 11 and Windows Server 2025 builds, and likely Windows 10 as well. It targets CVE-2026-50656, the RoguePlanet issue Microsoft fixed in July.
The new path abuses Defender’s cloud-hydration scan: one file is shown to the scanner, then swapped for different contents before the scan finishes. That lets a malicious DLL be treated like trusted system code and loaded by Windows, so patching the original RoguePlanet bug does not necessarily close this follow-on route.
For defenders, the important map is the endpoint itself: if Defender is active, a user-level foothold may still be able to cross into SYSTEM through cloud-file handling even on otherwise current machines. The exposure sits in the Defender behavior layer, not just in the original June/July race condition.
2 sources · Aug 13
CVSS 7.8 HIGH: microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender… EPSS 0.4% (28th percentile). Microsoft patch: Release Notes.
SecurityWeek
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
originalBleepingComputer
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named
originalPart of the PlainSec briefing for 2026-08-13
Every edition of this story: Defender Cloud Scan Opens a SYSTEM Path