After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug

A security researcher has unveiled a new vulnerability in the latest iterations of Windows, which enables hackers to gain system-wide access to users’ devices and sensitive data. This revelation comes in the wake of a legal threat from Microsoft, following the disclosure of previously unknown software flaws by the same researcher.

Details of the Vulnerability

The newly identified bug, named ShieldBreak, is the latest finding from security researcher Nightmare Eclipse. In recent months, they have disclosed multiple vulnerabilities affecting Microsoft’s suite of products, particularly Windows.

According to a post by Nightmare Eclipse, ShieldBreak exploits a flaw within Windows Defender, the integrated anti-malware and security engine. When successfully executed, this attack allows hackers to escalate their permissions from a low-level user to full administrative access, thereby compromising the device and its data.

Nightmare Eclipse has provided a proof-of-concept exploit in the form of a Windows application, which users must run to trigger the vulnerability. The flaw is said to affect Windows 10, Windows 11 (including the latest 25H2 version), and Windows Server 2025.

Security researcher Will Dormann has confirmed the functionality of the bug, noting that Windows Defender must be enabled for the exploit to be effective.

Background on the Exploit

This latest exploit builds upon an earlier vulnerability known as RoguePlanet, also developed by Nightmare Eclipse. Although Microsoft issued a patch for RoguePlanet, the researcher suggested that the fix was inadequate, as ShieldBreak demonstrates a complete bypass of the previous security measures.

As of now, Microsoft has not released a patch for the ShieldBreak vulnerability. A spokesperson for the company did not respond immediately to inquiries from TechCrunch. This bug is categorized as a zero-day, indicating that the software maker had no opportunity to address the flaw prior to its public disclosure.

The emergence of this zero-day vulnerability adds another chapter to the ongoing tension between the security researcher and Microsoft regarding the handling of bug reports. Nightmare Eclipse has expressed concerns over the treatment received from Microsoft, suggesting that the company did not adequately address their findings, leaving them with no option but to disclose the vulnerabilities publicly.

In May, Microsoft issued a blog post warning of potential legal action against security researchers, such as Nightmare Eclipse, who disclose zero-days outside the company’s established protocols. This stance drew significant criticism from the security community, many of whom echoed similar grievances regarding Microsoft’s approach to bug reporting. Although Microsoft later softened its tone in a social media post, the original blog post remains unchanged.

Current Context

The disclosure of ShieldBreak comes just a day after Microsoft’s scheduled monthly security patch releases, known as Patch Tuesday. This marks the second consecutive month where the number of patches has approached 500, a trend attributed to the company’s increasing reliance on artificial intelligence to identify and rectify security vulnerabilities.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Winsage
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug