Vulnerabilities & Exploits · Zero-Day Exploit

Defender Cloud Scan Opens a SYSTEM Path

Nightmare Eclipse published ShieldBreak on August 2026 Patch Tuesday, a proof-of-concept exploit for Microsoft Defender that can give a normal user SYSTEM privileges on current Windows 11 and Windows Server 2025 builds, and likely Windows 10 as well. It targets CVE-2026-50656, the RoguePlanet issue Microsoft fixed in July.

The new path abuses Defender’s cloud-hydration scan: one file is shown to the scanner, then swapped for different contents before the scan finishes. That lets a malicious DLL be treated like trusted system code and loaded by Windows, so patching the original RoguePlanet bug does not necessarily close this follow-on route.

For defenders, the important map is the endpoint itself: if Defender is active, a user-level foothold may still be able to cross into SYSTEM through cloud-file handling even on otherwise current machines. The exposure sits in the Defender behavior layer, not just in the original June/July race condition.

2 sources · Aug 13

CVE-2026-50656

NVD KEV

CVSS 7.8 HIGH: microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender… EPSS 0.4% (28th percentile). Microsoft patch: Release Notes.

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-08-13

Every edition of this story: Defender Cloud Scan Opens a SYSTEM Path

More from today