# New Zero-Day Exploit 'ShieldBreak' Elevates Threat Level for Windows Users

*Published August 14, 2026*
*Source: [https://www.securityweek.com/nightmare-eclipse-drops-windows-zero-day-exploit-shieldbreak/](https://www.securityweek.com/nightmare-eclipse-drops-windows-zero-day-exploit-shieldbreak/)*

## Executive Summary

Security researcher Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, targeting Microsoft Defender to elevate user privileges on Windows systems. Microsoft is investigating this vulnerability to mitigate potential risks to its users.

## Article

Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, has unveiled a concerning zero-day exploit named ShieldBreak, which allows users to gain elevated System privileges on Windows. This exploit was released in conjunction with the August 2026 Patch Tuesday updates, targeting a vulnerability in Microsoft Defender. The exploit affects the latest versions of Windows 11, Windows Server 2025, and likely Windows 10 as well. ShieldBreak leverages a flaw known as RoguePlanet, a race condition in Defender that was previously disclosed by Nightmare Eclipse in June. Although Microsoft issued patches for RoguePlanet in July, ShieldBreak circumvents these defenses by employing a different mechanism.

Security analysts such as Tharros Labs’s Will Dormann have dissected the exploit, explaining that it involves setting up a temporary directory as a Cloud Sync provider. The process involves manipulating Defender's scanning path to substitute a crucial system file with a malicious 'phoneinfo.dll' file, allowing attackers to execute code with SYSTEM privileges. This technique is distinct from RoguePlanet, which relied on filesystem race conditions to manipulate files.

Despite disagreements among experts on whether ShieldBreak is a bypass of RoguePlanet, the consensus is clear: ShieldBreak requires an active Defender to function, contrasting with RoguePlanet's independence from Defender's status. Microsoft is currently investigating the vulnerability and has reiterated its commitment to protecting customers through coordinated vulnerability disclosure, aiming to address issues before they are publicly exploited.
