Nightmare Eclipse, the pseudonymous security researcher turned Microsoft nemesis, has released another proof of concept (PoC) with source code for a vulnerability.
Called ShieldBreak the vulnerability lies in the Defender anti-malware tools and is a zero-day flaw for which no patch currently exists and allows for privilege escalation to the SYSTEM user in Windows.
The researcher said the PoC was tested in the latest version of Windows 11 25h2, and the Canary channel, as well as Windows Server 2025,
Nightmare Eclipse claims the PoC has a 100 percent success rate.
"Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well," Nightmare Eclipse wrote.
Nightmare Eclipse's exploit targets CVE-2026-50656, a Defender elevation-of-privilege flaw known as RoguePlanet that Microsoft patched in July and rated 7.8 on the CVSS scale.,
Will Dormann, principal vulnerability analyst at Tharros, confirmed the exploit works when Defender is enabled in Windows.
There is no evidence so far that ShieldBreak has been used in real-world attacks.
Security researcher Kevin Beaumont said he had tried the exploit and found it worked on the latest Windows 11, and published Microsoft Defender Advanced Hunting queries that defenders could use.
Beaumont said ShieldBreak operated differently from the original RoguePlanet race condition rather than simply replaying it.
ShieldBreak is the latest in a series of Windows exploits Nightmare Eclipse had released through 2026, a campaign fuelled by open grievance over Microsoft's handling of the researcher's disclosures.
Microsoft threatened legal measures against the researcher and others disclosing serious bugs but had to back down following a backlash from the security industry community.

Forrester's AI Forum Sydney
NiCE World APAC 2026
The 2026 iAwards
Integrate 2026
Security Exhibition & Conference



