Microsoft’s recent legal warnings have not deterred security researcher Nightmare Eclipse, who has unveiled a significant new vulnerability in Windows. Just weeks after the tech giant cautioned researchers about potential legal repercussions for disclosing undisclosed bugs outside its official channels, Nightmare Eclipse introduced a concerning exploit known as ShieldBreak.
What exactly does ShieldBreak do?
ShieldBreak specifically targets Windows Defender, the integrated anti-malware solution included with every Windows operating system. When successfully exploited, this vulnerability allows an attacker to escalate privileges from a low-level user account to full system access, effectively granting control over the entire device.
Nightmare Eclipse has made the proof of concept available as a downloadable Windows application, meaning that an individual would need to execute it for the exploit to take effect. The researcher has indicated that ShieldBreak impacts Windows 10, Windows 11, and Windows Server 2025. Security expert Will Dormann has confirmed the exploit’s functionality, noting that Windows Defender must be activated for the attack to succeed.
This is not the first time Nightmare Eclipse has made headlines. ShieldBreak is said to build upon a previous exploit named RoguePlanet. Although Microsoft did release a patch for RoguePlanet, the researcher contends that the fix was insufficient, allowing ShieldBreak to bypass it entirely.
Why is Microsoft caught in the middle again?
The ongoing saga highlights a protracted conflict between Nightmare Eclipse and Microsoft regarding the company’s approach to bug reporting. The researcher has accused Microsoft of mishandling past disclosures, leading to the public release of several vulnerabilities instead of their quiet remediation.
In May, Microsoft’s situation worsened when it threatened legal action against researchers who disclosed zero-day vulnerabilities outside its established guidelines. This move prompted a strong backlash from the security community, resulting in Microsoft softening its stance on social media, although the original blog post outlining its position remains active.
Currently, Microsoft has acknowledged the reported vulnerability and stated that it is actively investigating the matter. As of now, no patch has been released, making this a critical issue for users of Windows to monitor closely.