Urgent.News

What's breaking now, across thousands of outlets.

Tech

Researcher bypasses Microsoft Defender security patch, seizing control

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security . Nightmare Eclipse has not provided the further details we…

Researcher bypasses Microsoft Defender security patch, seizing control

Microsoft patched a critical hole in Microsoft Defender just weeks ago, but a cybersecurity researcher named Nightmare Eclipse has reportedly bypassed the security measure. The research was detailed in a series of public posts, and the bypass, dubbed ShieldBreak, could grant attackers system-level control once they have any level of access.

Nightmare Eclipse did not provide further details, but Microsoft responded by stating that they are aware of the vulnerability and actively investigating the claims. ShieldBreak potentially poses a more significant threat than previous bypasses, as it requires attackers to gain system access first, typically through phishing scams.

Once inside, the attacker can gain full admin/root access, which is a concerning psychological component because it targets a recently patched security vulnerability. This issue raises doubts about the integrity of Microsoft's remediation efforts. Justin Greis, CEO of Acceligence, a consulting firm, expressed concern that CISOs who have already deployed the patch might falsely feel protected.

The patch bypass directly challenges the effectiveness of Microsoft's remediation, potentially reducing trust in official patches. Enterprises may question whether they have truly removed the exposure after deploying the patch. Flavio Villanustre, CISO for LexisNexis Risk Solutions Group, emphasized the timing of the proof of concept (PoC) release, suggesting it aimed to pressure Microsoft for a fix.

The PoC's release coincides with Microsoft's typical patch release schedule, potentially leaving organizations vulnerable for another four weeks. Brian Levine, a cybersecurity consultant, warned that ShieldBreak can transform an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege level on the endpoint.

He recommended that CISOs take an aggressive defensive stance, such as relying on defense in depth with application allowlisting and tightening local admin rights. While the PoC's effectiveness has been independently verified, cybersecurity experts urge caution, as it may still require further verification before being considered a genuine threat.

Written by urgent.news from Computerworld's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at computerworld.com →

More in Tech

More from Wednesday 12 August →