All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Researcher Discloses Windows Zero-Day After Microsoft Legal Threat

Created at 12 Aug · 3:31 PM1 source↑ Market-relevant
IN SHORT

Security researcher Nightmare Eclipse has published details of a new Windows zero-day vulnerability, dubbed ShieldBreak, which allows for system-wide access. This disclosure follows a prior legal threat from Microsoft over previous bug disclosures, highlighting ongoing tensions between the researcher and the software giant.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

500bugs patched in monthly release

Who's Involved

Nightmare Eclipse
security researcher who published the ShieldBreak zero-day
Microsoft
software giant facing legal threats and bug disclosures
Will Dormann
security researcher who verified the ShieldBreak exploit
Researcher Discloses Windows Zero-Day After Microsoft Legal Threat

↳ Why This Matters

The disclosure of a critical zero-day vulnerability like ShieldBreak poses a significant risk to Windows users and organizations, potentially leading to widespread data breaches and system compromises. The ongoing conflict between researchers and Microsoft highlights systemic issues in bug disclosure processes and could impact future vulnerability reporting.

Key facts

  • A new Windows zero-day vulnerability, ShieldBreak, has been publicly disclosed.
  • The exploit allows for system-wide access to a user's device and data.
  • ShieldBreak targets a flaw in Windows Defender.
  • The vulnerability affects Windows 10, Windows 11, and Windows Server 2025.
  • Microsoft has not yet issued a patch for the ShieldBreak vulnerability.
  • The disclosure follows a period of legal threats from Microsoft towards security researchers.

A security researcher known as Nightmare Eclipse has publicly disclosed a new zero-day vulnerability in Windows, dubbed ShieldBreak, which grants attackers system-wide access to a user's device and data. This disclosure comes despite Microsoft having previously threatened legal action against researchers for releasing details of unknown software flaws outside of the company's established disclosure policies.

The ShieldBreak vulnerability exploits a flaw within Windows Defender, the built-in anti-malware engine. According to the researcher's post, a successful attack allows an attacker to escalate their privileges from a low-level user to gain full control over the device and its data. The proof-of-concept exploit was released as a Windows application that requires user execution. The bug is confirmed to work on Windows 10, Windows 11 (including version 25H2), and Windows Server 2025, with verification provided by security researcher Will Dormann, who noted that Windows Defender must be enabled for the exploit to function.

This latest exploit builds upon a previous vulnerability called RoguePlanet, developed by the same researcher. While Microsoft had previously patched RoguePlanet, Nightmare Eclipse suggests that the fix was insufficient and that ShieldBreak demonstrates a complete bypass of the earlier patch. Microsoft has not yet released a fix for ShieldBreak, classifying it as a zero-day due to the immediate public disclosure without prior notification to the software maker.

The ongoing tension between Nightmare Eclipse and Microsoft stems from the researcher's claims of mistreatment and inadequate handling of their bug reports by the company. This has led to public disclosures of several Windows bugs, some of which have reportedly been exploited in real-world attacks. Microsoft's initial threat of legal action in May was met with significant criticism from the security community, though the company later softened its stance publicly, its original blog post remains published.

Frequently asked questions

ShieldBreak is a newly disclosed zero-day vulnerability in Microsoft Windows that allows attackers to gain system-wide access to a user's device and data.

The vulnerability affects Windows 10, Windows 11 (including the latest 25H2 version), and Windows Server 2025.

No, Microsoft has not yet released a patch for the ShieldBreak vulnerability.

A zero-day vulnerability is a security flaw that is unknown to the software vendor, meaning they have had no time to develop a patch before it is publicly disclosed or exploited.

What Happens Next

01Microsoft is expected to develop and release a patch for the ShieldBreak vulnerability.
02Users are advised to monitor for security updates from Microsoft.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Security researcher Nightmare Eclipse published details of a new Windows zero-day vulnerability named ShieldBreak.
The vulnerability allows hackers to gain system-wide access to a user's device and data.
ShieldBreak exploits a flaw in Windows Defender, requiring the user to run a proof-of-concept app.
The bug affects Windows 10, Windows 11, and Windows Server 2025.
Security researcher Will Dormann verified the exploit's functionality.
This exploit builds upon an earlier vulnerability, RoguePlanet, for which Microsoft had previously issued a patch.
Microsoft has not yet released a patch for ShieldBreak.
Microsoft had previously threatened legal action against researchers for disclosing zero-days outside their policies.

Sources

T1
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bugTechCrunch

Related Stories

Researchers use AI to find Zoom screen sharing vulnerabilities
12 Aug · 1:46 PM
Uber Freight Investigating Cyber Incident After Hacker Claims
11 Aug · 7:46 PM
Meta AI glasses face criminal complaint in Germany
12 Aug · 4:06 PM
OpenAI Executive Brad Lightcap Departs Amid IPO Preparations and Leadership Turnover
11 Aug · 10:11 PM
OpenAI launches ChatGPT desktop app for Linux
11 Aug · 7:40 PM