A publicly disclosed zero-day dubbed ShieldBreak (CVE-2026-69414) allows a local attacker with limited privileges to escalate to SYSTEM on Windows systems where Microsoft Defender is enabled. Reporting says the flaw affects the Microsoft Malware Protection Engine and serves as a bypass of Microsoft’s earlier fix for RoguePlanet (CVE-2026-50656), indicating the prior remediation was incomplete. Microsoft has acknowledged the issue and said it is working on a patch, but no release date has been announced.
Technical analysis shows the exploit chains Cloud Files abuse, NT Object Manager namespace manipulation, direct use of Defender functionality through MpClient.dll, a remediation timing race, and Windows Error Reporting task abuse to coerce Defender into writing an attacker-controlled DLL to C:\Windows\System32\phoneinfo.dll, which is then executed by wermgr.exe as SYSTEM. Researchers reproduced the proof of concept on fully patched Windows 11 24H2 and Windows Server 2025 systems with default Defender settings, with elevation reportedly occurring in roughly eight to twelve seconds; key detection opportunities include creation of phoneinfo.dll in System32, MpClient.dll loading by non-Defender processes, suspicious activity under \BaseNamedObjects\Restricted\, and wermgr.exe loading the planted DLL.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed on August 17, 2026 that it was working on a patch for ShieldBreak, tracked as CVE-2026-69414. No patch release date was announced at that time.
After Microsoft's August 2026 Patch Tuesday, disclosure actor Nightmare-Eclipse publicly released the ShieldBreak proof of concept, a local privilege escalation chain abusing Microsoft Defender remediation to gain SYSTEM privileges. Reporting says the disclosure was made without prior notification to Microsoft.
Microsoft patched RoguePlanet (CVE-2026-50656) in July 2026. Subsequent reporting said ShieldBreak showed the earlier fix was incomplete.
RoguePlanet, a Microsoft Defender privilege escalation vulnerability tracked as CVE-2026-50656, was disclosed in June 2026. Later reporting described ShieldBreak as a bypass of the patch for this earlier flaw.
LevelBlue OpsCTI and THOR reviewed and reproduced the full ShieldBreak exploitation chain on fully patched Windows 11 24H2 and Windows Server 2025 systems with default Windows Defender settings. They reported the exploit could elevate a standard user to SYSTEM in roughly eight to twelve seconds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcelevelblue.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.