Key facts
- A new Windows zero-day vulnerability, ShieldBreak, has been publicly disclosed.
- The exploit allows for system-wide access to a user's device and data.
- ShieldBreak targets a flaw in Windows Defender.
- The vulnerability affects Windows 10, Windows 11, and Windows Server 2025.
- Microsoft has not yet issued a patch for the ShieldBreak vulnerability.
- The disclosure follows a period of legal threats from Microsoft towards security researchers.
A security researcher known as Nightmare Eclipse has publicly disclosed a new zero-day vulnerability in Windows, dubbed ShieldBreak, which grants attackers system-wide access to a user's device and data. This disclosure comes despite Microsoft having previously threatened legal action against researchers for releasing details of unknown software flaws outside of the company's established disclosure policies.
