IT-PUB NEWS

Windows zero-day goes public after Microsoft threat

13.08.2026 13:03 • Author: IT-PUB
Windows zero-day goes public after Microsoft threat

Nightmare Eclipse disclosed ShieldBreak, a Windows Defender flaw affecting Windows 10, 11, and Server 2025, while Microsoft still has no patch.

A security researcher has published details of a new Windows zero-day that can let an attacker move from a low-level account to full control of a device and its data. The disclosure comes just weeks after Microsoft threatened legal action over the publication of previously unknown flaws. That adds fresh tension to an already strained relationship. It also leaves Windows users facing a serious security issue without a patch.

The vulnerability, called ShieldBreak, was published by the researcher known as Nightmare Eclipse, who has recently disclosed several bugs affecting Microsoft products. The case stands out not only because of the potential impact on Windows systems, but also because it has become part of a public fight over how software flaws should be reported and disclosed.

ShieldBreak exploits Windows Defender

According to Nightmare Eclipse’s post, ShieldBreak abuses a flaw in Windows Defender, the anti-malware and security engine built into Windows. If the exploit succeeds, an attacker can escalate privileges and gain system-wide access to the device and the data stored on it.

The researcher released a proof-of-concept exploit as a Windows app. In practice, that means the user has to run the app for the bug to be triggered. Nightmare Eclipse said the flaw affects Windows 10, Windows 11, including the latest 25H2 version, and Windows Server 2025.

Security researcher Will Dormann verified that the bug works and said Windows Defender must be enabled for the exploit to function, as IT-PUB News reports.

ShieldBreak follows the earlier RoguePlanet exploit

Nightmare Eclipse said ShieldBreak builds on an earlier exploit called RoguePlanet. Microsoft patched RoguePlanet, but the researcher suggested the fix was not sufficient and that ShieldBreak completely bypasses the earlier patch.

That helps explain why the new disclosure quickly drew attention. It is not just another bug report, but a claim that Microsoft’s earlier fix may not have fully addressed the underlying issue.

Microsoft has not yet released a patch for ShieldBreak. When contacted by TechCrunch, a Microsoft spokesperson did not immediately comment.

Microsoft and Nightmare Eclipse are still fighting over disclosure

The release is the latest chapter in a longer dispute between Nightmare Eclipse and Microsoft over how the company handles bug reports. In blog posts, the researcher said Microsoft mistreated them and did not deal with their reports adequately, implying that public disclosure was the only remaining option.

Nightmare Eclipse has also previously published other Windows bugs that were later exploited in real-world attacks against organizations. That gives the latest disclosure extra weight, since the risk here goes beyond a purely theoretical flaw.

Microsoft entered the debate directly in May, when it published a blog post threatening legal action against security researchers, including Nightmare Eclipse, if they released details of zero-days outside the company’s disclosure policies. The statement drew heavy criticism from the security community, with many people describing similar experiences with Microsoft’s handling of bug reports. Microsoft later softened its position in a social media post, although the original blog post remains online unchanged.

Patch Tuesday passed without a fix

ShieldBreak was disclosed a day after Microsoft’s monthly Patch Tuesday release. The timing matters: Microsoft had already shipped its regular round of security fixes before this new flaw became public.

The source also notes that this is the second month in a row in which Microsoft’s patch count has reached around 500 bugs. That increase has been linked to the company’s growing use of AI to find and remove security flaws.

For Windows users and organizations running Microsoft software, the immediate problem is straightforward. ShieldBreak is now public, and Microsoft still has no patch for it. Until that changes, the dispute over disclosure rules is no longer just an argument between a company and a researcher — it has direct consequences for devices, business systems, and the people who depend on them every day.


Improve SEO for a small/medium business website for $50