CVE-2026-50656 ShieldBreak Bypasses Defender Patch
ShieldBreak targets CVE-2026-50656 and, according to multiple reports, can raise privileges to SYSTEM on fully patched Windows.
A researcher has published ShieldBreak, a PoC that claims to bypass Microsoft Defender’s fix for CVE-2026-50656. Multiple reports say it requires prior local access and can escalate a session to SYSTEM.
ShieldBreak is a proof of concept published by a researcher that claims to bypass Microsoft Defender’s patch for CVE-2026-50656, also identified as RoguePlanet, and can elevate privileges to SYSTEM on Windows with Defender enabled. The technique was reported by The Hacker News on August 12, 2026, and later analyzed by several security firms and specialist publications.
What does the PoC do?
According to Braincap, the technique can elevate privileges to SYSTEM on Windows, but it requires the attacker to already have local access to the machine. The Hacker News also reported that Will Dormann validated the PoC and noted that Defender must be enabled for the exploit to work. Computerworld added that the PoC gives system-level control to attackers who have already obtained access and that, according to Steven Eric Fisher, there would be independent confirmation that ShieldBreak works.
How does it work?
Tanium said that Nightmare, also known as Chaotic Eclipse, published ShieldBreak on August 11 and 12, 2026, as a PoC that reopens the same race condition as RoguePlanet, but with a different technique. The chain described combines registration of a cloud storage provider, use of CLFS, and Object Manager symbolic links to replace a system file reported as phoneinfo.dll during Defender processing.
SecurityWeek expanded on the technical flow and said the exploit registers a temporary directory as a Cloud Sync provider, plants an EICAR file to force a scan, manipulates CLFS to redirect hydration metadata toward phoneinfo.dll in System32, and then triggers the QueueReporting scheduled task to obtain a shell with SYSTEM privileges.
What is the scope and mitigation status?
ThreatLocker described ShieldBreak as a PoC bypass for Microsoft’s fix for CVE-2026-50656 and said that, at the time, there was no specific patch for ShieldBreak. SecurityArsenal agreed that there was no dedicated fix and that mitigation depended on compensating controls, Defender hardening, and custom detection rules.
Malware.news said the bypass works with a 100 percent success rate on Windows 11 25H2, including the Canary channel, and on Windows Server 2025, with reliability higher than the original RoguePlanet exploit. The Register added that Windows 10 and its server editions remain vulnerable to the same underlying weakness, although the public PoC does not include official support for those versions.
What does the CVE context say?
The official NVD listing for CVE-2026-50656 describes RoguePlanet as a privilege escalation in Microsoft’s Malware Protection Engine for Microsoft Defender, and says it is recognized by Microsoft. Blogspan.net noted that the security advisory tied to that CVE was not updated after ShieldBreak was published and remained at revision 2.0 from July 8, 2026, despite the PoC showing a complete bypass of the fix.
CyberWorldOps attributed the exploit to Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse, and placed it within a sustained campaign of zero-day releases against Microsoft Defender. The Register, meanwhile, quoted Kevin Beaumont as saying ShieldBreak presents itself as a direct bypass of RoguePlanet, but that its method of operation is technically different from the original exploit.
Sources
- ShieldBreak Zero-Day PoC Claims Microsoft Defender ...thehackernews.com· The Hacker News
- CVE-2026-50656 Detailnvd.nist.gov· NVD (NIST)
- Microsoft Defender bypassed again (ShieldBreak): PoC grants SYSTEM — but it needs local access first — Braincapbraincap.ro· Braincap
- ShieldBreak PoC Bypasses MS Defender Patch for SYSTEMcyberworldops.eu· CyberWorldOps
- Researcher bypasses Microsoft Defender patch, seizing ...computerworld.com· Computerworld
- NightmareEclipse releases new PoC, ShieldBreak, exploits ...threatlocker.com· ThreatLocker
- ShieldBreak: The Windows Defender 0-Day with No Patchtanium.com· Tanium
- ShieldBreak: Windows Zero-Day That Breaks Microsoft's RoguePlanet Fixmalware.news· malware.news
- Nightmare Eclipse Drops Windows Zero-Day Exploit ShieldBreaksecurityweek.com· SecurityWeek
- Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windowstheregister.com· The Register
- ShieldBreak PoC Claims Microsoft Defender Patch Bypass for CVE-2026-50656 (RoguePlanet) — Detection, Hunting, and Mitigation Guidesecurityarsenal.com· SecurityArsenal
- ShieldBreak: Defender-Patch vom Juli umgangenblogspan.net· Blogspan.net



