Defender Cloud Scan Opens a SYSTEM Path

Nightmare Eclipse published ShieldBreak on August 2026 Patch Tuesday, a proof-of-concept exploit for Microsoft Defender that can give a normal user SYSTEM privileges on current Windows 11 and Windows Server 2025 builds, and likely Windows 10 as well. It targets CVE-2026-50656, the RoguePlanet issue Microsoft fixed in July. The new path abuses Defender’s cloud-hydration scan: one file is shown to the scanner, then swapped for different contents before the scan finishes. That lets a malicious DLL be treated like trusted system code and loaded by Windows, so patching the original RoguePlanet bug does not necessarily close this follow-on route. For defenders, the important map is the endpoint itself: if Defender is active, a user-level foothold may still be able to cross into SYSTEM through cloud-file handling even on otherwise current machines. The exposure sits in the Defender behavior layer, not just in the original June/July race condition.

Part of the PlainSec briefing for 2026-08-13

Every edition of this story: Defender Cloud Scan Opens a SYSTEM Path

Sources