Windows security vulnerability exposes ShieldBreak exploit with no fix

A security researcher has published proof-of-concept details for a new Windows security vulnerability that could hand hackers full control of a victim’s device, weeks after Microsoft threatened legal action over exactly this kind of public disclosure. The flaw, dubbed ShieldBreak, targets a weakness inside Windows Defender, the anti-malware engine built directly into every modern copy of Windows, and it lands amid an increasingly bitter dispute between Microsoft and the researcher who found it.
Key takeaways
- ShieldBreak is a new zero-day that exploits a flaw in Windows Defender’s security engine to escalate a low-level user to full system access.
- It affects Windows 10, Windows 11 (including the newest 25H2 build), and Windows Server 2025.
- The exploit requires a victim to run a malicious Windows app; researcher Will Dormann confirmed it works when Windows Defender is enabled.
- It builds on an earlier flaw called RoguePlanet, which Microsoft patched incompletely, according to the researcher who found both.
- Microsoft has not released a fix for ShieldBreak and did not respond to a request for comment from TechCrunch.
New zero-day vulnerability exploits Windows Defender flaw
ShieldBreak works by abusing a weakness inside Windows Defender itself, turning the very tool meant to catch malware into the doorway attackers need. Once triggered, a successful attack lets a hacker jump from limited, low-level access on a machine to complete control over the device and everything stored on it.
… Continue reading the full article at the original source below.


