New Defender exploit defeats RoguePlanet patch, hands out SYSTEM shells

A researcher's ShieldBreak PoC claims to bypass Microsoft's fix for the Defender RoguePlanet flaw.

CSBadmin
2 Min Read

A Windows proof-of-concept called ShieldBreak is circulating as a supposed bypass for Microsoft’s RoguePlanet fix. That fix covered CVE-2026-50656, a flaw in the Defender engine, and the new exploit comes from researcher Chaotic Eclipse, also known as Nightmare Eclipse. It reportedly converts low-privilege access into SYSTEM-level code execution with a claimed 100 percent success rate on Windows 11 25H2 and Windows Server 2025. Windows 10 remains exposed too.

RoguePlanet is a CVSS 7.8 local privilege escalation race condition in the Malware Protection Engine that Microsoft fixed in early July. Independent researchers, including Kevin Beaumont, have since confirmed ShieldBreak works, though it uses a different exploitation path through the Defender Cloud Filter API rather than replaying the original filesystem race.

The bypass stings because organizations that deployed the RoguePlanet fix may believe they are protected. Consultants warn that a public patch bypass undermines confidence in remediation and that CISOs should assume the exposure persists. Recommended defenses include application allowlisting with WDAC or AppLocker, tightening local admin rights, and hunting for interactive shells running under MsMpEng.exe.

Microsoft acknowledged the report, saying it is investigating the validity of the claims. The researcher behind ShieldBreak has repeatedly published zero-day disclosures after a public falling-out with Microsoft’s security response team, and dropped this one before the next scheduled Patch Tuesday.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.