Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

Nightmare Eclipse, a notorious figure in the realm of cybersecurity, has resurfaced with a new zero-day exploit dubbed ShieldBreak. This latest vulnerability has the potential to bypass Microsoft’s recent RoguePlanet patch (CVE-2026-50656), enabling attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit’s efficacy has been corroborated by Kevin Beaumont, a former Microsoft employee and security expert, who confirmed its functionality on the latest version of Windows 11.

Beaumont has proactively shared three detection methods and hunting queries for ShieldBreak, equipping defenders with tools to swiftly identify any lurking threats. Until Microsoft addresses this newly unveiled zero-day, utilizing these queries is highly recommended for those looking to bolster their defenses.

ShieldBreak marks the tenth zero-day release from Nightmare Eclipse since the commencement of their aggressive campaign against Microsoft in early April. Speculation suggests that the individual behind this prolific bug-hunting operation may be a disgruntled former Microsoft employee. True to form, this latest exploit was released mere hours after Microsoft’s monthly Patch Tuesday, which addressed 421 security vulnerabilities—yet ShieldBreak was notably absent from the list of fixes.

This local privilege escalation exploit allows attackers to elevate their privileges to SYSTEM level. Nightmare Eclipse claims that the proof of concept (PoC) was tested on the latest version of Windows 11 (25h2) and Windows Server 2025, boasting a 100% success rate. While Windows 10 and its server editions are not currently supported, they remain vulnerable to ShieldBreak.

Nightmare asserts that ShieldBreak serves as a patch bypass for the earlier RoguePlanet vulnerability, although Beaumont clarifies that the two exploits function quite differently. He elaborates that RoguePlanet exploited a filesystem race condition vulnerability, while ShieldBreak employs a user-mode callback hook to alter file contents during a Defender cloud-hydration scan via the Cloud Filter API.

A Microsoft spokesperson has acknowledged awareness of the reported vulnerability and stated that the company is actively investigating the claims. They emphasized Microsoft’s commitment to addressing security issues and updating affected products promptly. The spokesperson also reiterated the importance of coordinated vulnerability disclosure, which safeguards customers and supports the research community by ensuring thorough investigations before public announcements.

MORE CONTEXT

This latest zero-day follows Nightmare Eclipse’s previous release in July, known as LegacyHive, which targets Windows’ user hives without an official patch. Additionally, a June zero-day named GreatXML allows local attackers with administrative rights to bypass BitLocker encryption through manipulation of the Windows Recovery Environment. While Nightmare Eclipse’s earlier seven Windows bugs have been patched, the recent exploits remain unaddressed, raising concerns within the cybersecurity community.

In a notable turn of events, Microsoft had previously threatened legal action against Nightmare Eclipse in May. However, after facing significant backlash from the cybersecurity community, the tech giant reconsidered its stance on enforcing its vulnerability disclosure rules.

Winsage
Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows