Published Security3 min read
A Second SYSTEM Path Through Defender, and a Fight Over Whether It Is a Patch Bypass
ShieldBreak, published on August Patch Tuesday, takes a local user to SYSTEM on fully updated Windows 11 25H2 and Server 2025. The researcher calls it a bypass of July's RoguePlanet fix.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a proof-of-concept exploit dubbed ShieldBreak targeting a vulnerability in Microsoft Defender that allows any user to gain SYSTEM privileges.
- The ShieldBreak proof-of-concept was published on August 2026 Patch Tuesday.
- Chaotic Eclipse said: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass."
- The researcher said the PoC was tested on the latest Windows 11 25H2 including the Canary channel and on Windows Server 2025 with a 100% success rate, and that Windows 10 and respective server editions are not currently supported by the PoC but are vulnerable to ShieldBreak as well.
- CVE-2026-50656, named RoguePlanet, is a race condition and local privilege escalation flaw with a CVSS score of 7.8 affecting the Microsoft Malware Protection Engine (mpengine.dll) used by Defender, which could allow an attacker with access to a system to obtain higher privileges and potentially compromise security controls.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A researcher who publishes as Nightmare Eclipse, also known as Chaotic Eclipse, dropped a working proof-of-concept on August 2026 Patch Tuesday that turns any local user into SYSTEM through Microsoft Defender, and calls it a full bypass of Microsoft's July fix for CVE-2026-50656 [1][2][3]. Two analysts who pulled the exploit apart say the bypass label is wrong, and that matters operationally because the two bugs have different prerequisites and therefore different containment options [9][11].
RoguePlanet, CVE-2026-50656, was a race condition in the Microsoft Malware Protection Engine, mpengine.dll, rated CVSS 7.8, a local privilege escalation that could hand an attacker with a foothold higher privileges and let them compromise security controls [5]. The same researcher dropped it as a zero-day on June 9, Microsoft acknowledged it on June 16, and shipped fixes on July 9 [6]. That is seven days to acknowledgement and 30 days to a patch [19][20]. The fix then survived one monthly cycle before a public claim of bypass landed on the next Patch Tuesday [21].
According to Will Dormann of Tharros Labs, ShieldBreak sets up a temporary directory registered as a Cloud Sync provider, plants an EICAR file, steers Defender's scan path to System32, uses CLFS to swap the identity file and hydration data into a phoneinfo.dll in System32, and then runs the QueueReporting scheduled task [7]. Dormann notes that wer.dll contains explicit code to load phoneinfo.dll, a file that does not exist by default on Windows, so the attacker's DLL runs and spawns conhost.exe as SYSTEM [8].
Both Dormann and Kevin Beaumont dispute that this is a RoguePlanet bypass, because the mechanics differ [9]. Beaumont describes RoguePlanet as a filesystem race condition using virtual disks and NT native file manipulation to trick the quarantine process into overwriting system files, and ShieldBreak as a user-mode callback hook that changes file contents during a Defender cloud-hydration scan via the Cloud Filter API [10]. Dormann adds the point with the most operational weight: ShieldBreak appears to require Defender to be active, while RoguePlanet did not [11]. Beaumont has published detection queries for the PoC [12].
The researcher's own testing claims are unverified by anyone else in the record: 100 percent success on Windows 11 25H2, including the Canary channel, and on Windows Server 2025, with Windows 10 described as vulnerable but not currently supported by the PoC [4]. The researcher also claims Defender may leak 8 bytes of data under certain conditions [13].
The context is a running dispute rather than a coordinated disclosure. The researcher has criticised Microsoft for revoking access to their MSRC account, rejecting reports, and not paying out [15]. Microsoft's Security Response Center called the zero-day dumps irresponsible at the end of May, said details were not shared before release, named RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma and MiniPlasma as not responsibly disclosed, and said its teams had been working around the clock against attackers who picked up the published code and ran with it [16]. The drops keep arriving on schedule: YellowKey and GreenPlasma in May against BitLocker and CTFMON [14], LegacyHive against the User Profile Service hours after July Patch Tuesday [17], and generally right after Patch Tuesday [18].
Watch for a Microsoft acknowledgement and a separate CVE, since neither report carries a vendor statement on ShieldBreak [22]. If the RoguePlanet timeline repeats, that is roughly a week to acknowledgement and a month to a fix [19][20]. Until then the honest reading is a live local-to-SYSTEM path on patched hosts, detectable with Beaumont's queries [12], and dependent on Defender running [11], which is not a knob most estates can turn off.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a proof-of-concept exploit dubbed ShieldBreak targeting a vulnerability in Microsoft Defender that allows any user to gain SYSTEM privileges.
- [2]
The ShieldBreak proof-of-concept was published on August 2026 Patch Tuesday.
- [3]
Chaotic Eclipse said: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass."
- [4]
The researcher said the PoC was tested on the latest Windows 11 25H2 including the Canary channel and on Windows Server 2025 with a 100% success rate, and that Windows 10 and respective server editions are not currently supported by the PoC but are vulnerable to ShieldBreak as well.
- [5]
CVE-2026-50656, named RoguePlanet, is a race condition and local privilege escalation flaw with a CVSS score of 7.8 affecting the Microsoft Malware Protection Engine (mpengine.dll) used by Defender, which could allow an attacker with access to a system to obtain higher privileges and potentially compromise security controls.
- [6]
Nightmare Eclipse dropped RoguePlanet as a zero-day on June 9, Microsoft acknowledged the exploit on June 16, and Microsoft released fixes for it on July 9.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi PaganiniAug 12ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
- securityweek.comIonut ArghireAug 13Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Additional citations
- SecurityWeek; Security Affairs
- SecurityWeek
- Chaotic Eclipse, quoted by Security Affairs



