Security Researcher Releases New Windows Zero-Day After Microsoft’s Legal Threats

A security researcher, known by the alias Nightmare Eclipse, has publicly disclosed a new vulnerability in the latest versions of Windows, named ‘ShieldBreak.’ This flaw enables attackers to gain full system access to a user’s device and data. The disclosure comes despite previous legal threats from Microsoft concerning the release of unpatched software vulnerabilities.

ShieldBreak exploits a weakness in Windows Defender, the built-in anti-malware engine in Windows. By leveraging this flaw, an attacker can escalate their privileges from a standard user to full system access. The proof-of-concept exploit, released as a Windows application, requires user execution to initiate the attack. This vulnerability affects Windows 10, Windows 11 (including the latest 25H2 version), and Windows Server 2025.

Security expert Will Dormann has confirmed the exploit’s functionality, noting that Windows Defender must be active for the attack to succeed. This new exploit builds upon a previous vulnerability, ‘RoguePlanet,’ also discovered by Nightmare Eclipse. Although Microsoft issued a patch for RoguePlanet, the researcher suggests that the fix was inadequate, as ShieldBreak effectively bypasses the earlier patch.

Microsoft has yet to release a patch for ShieldBreak. The company has not provided immediate comments regarding this new vulnerability. As ShieldBreak was disclosed without prior notice to Microsoft, it is classified as a zero-day vulnerability, leaving systems exposed until a fix is developed.

This incident is the latest in an ongoing dispute between Nightmare Eclipse and Microsoft over the handling of vulnerability disclosures. The researcher has accused Microsoft of mishandling their bug reports, leading to the decision to publicly release the vulnerabilities. Previous disclosures by Nightmare Eclipse have been exploited in real-world attacks targeting various organizations.

In May, Microsoft published a blog post threatening legal action against researchers who disclose zero-day vulnerabilities outside of the company’s established policies. This stance faced significant criticism from the security community, with many professionals sharing similar experiences regarding Microsoft’s handling of vulnerability reports. Although Microsoft later retracted its threat in a social media post, the original blog post remains unchanged.

The release of ShieldBreak occurred shortly after Microsoft’s monthly security update, known as Patch Tuesday. Notably, this marks the second consecutive month where the number of patches has reached approximately 500, a surge attributed to the company’s increased use of artificial intelligence to identify and address security flaws.

The public disclosure of ShieldBreak underscores the ongoing tension between security researchers and software vendors over vulnerability reporting and patching processes. It highlights the critical need for transparent and cooperative relationships to ensure the timely resolution of security issues, thereby protecting users from potential exploits.