Microsoft's nemesis drops new zero-day privilege escalation vulnerability — attack grants system-level privileges, but it could already be patched
Nightmare Eclipse drops ShieldBreak, another Windows zero-day privilege escalation vulnerability, but Microsoft has rushed quickly to block it with Defender
Proactive hacker and Microsoft critic, Nightmare Eclipse, has unveiled ShieldBreak, a fresh Windows zero-day vulnerability designed to grant SYSTEM-level privileges simply by executing code as a standard user. Although Eclipse has typically outpaced Microsoft, it appears the company might be closing the gap, as our preliminary testing indicates Defender detects the exploit and it may have already been patched as of last Tuesday.
ShieldBreak is essentially an evolution of the previously disclosed RoguePlanet vulnerability within Windows Defender's subsystems. Microsoft, according to the author, failed to adequately address RoguePlanet, and ShieldBreak could potentially circumvent the recently enhanced safeguards. The proof-of-concept code aims to launch a super-elevated command prompt with SYSTEM privileges, surpassing even Administrator access.
The author asserts that ShieldBreak affects the most recent iterations of Windows 11, Windows Server 2025, and Windows 10, although the proof-of-concept is currently confined to the first two operating systems. While researchers like Kevin Beaumont and Will Dormann claim to have successfully replicated the exploit, our brief testing on a Windows 11 virtual machine did not produce any notable results.
The virtual machine in question was recently updated with the latest Windows 11 patches and is currently running version 10.0. 26200.9168. Given that Microsoft released a comprehensive patch last Tuesday, it's plausible that they resolved the underlying issue ShieldBreak exploits. However, given that Microsoft just published a comprehensive patch last Tuesday, there's a strong likelihood that they addressed the vulnerability ShieldBreak exploited.
Nevertheless, given that Microsoft just released a comprehensive patch last Tuesday, it's worth emphasizing that a single instance doesn't constitute comprehensive research. As such, we strongly advise caution and recommend conducting independent testing before concluding that the bug has been entirely eradicated. Microsoft has already published a Defender detection for the exploit.
During our verification process, we noted a 20-minute interval between the two tests, as illustrated in the accompanying image. (Image credit: Future) Even if Microsoft resolves the issue, it's important to note that not all users promptly install updates, and corporations often delay patches due to concerns about introducing new problems.
Consequently, a substantial portion of the global machine population may still be susceptible to ShieldBreak. Details about Nightmare Eclipse are scarce, beyond their apparent disdain for Microsoft and the assertion that the company has significantly impacted their lives. Cybersecurity experts such as Brian Krebs and Kevin Beaumont suggest that Eclipse could be a disgruntled former Microsoft employee.
Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.