Microsoft Rushes To Patch ShieldBreak Zero-Day Flaw In Windows Defender
Microsoft has found itself in the spotlight again after its antivirus Windows Defender proved unable to withstand a new threat. The research group Nightmare-Eclipse, previously known for attacks on the RoguePlanet platform, introduced a new exploit called ShieldBreak. This is an evolution of the previous vulnerability that allows attackers to escalate privileges and gain full control over the system.
Why the July patch didn't work?
It was previously reported that the "Patch Tuesday" updates in July were supposed to fix issues related to RoguePlanet. However, according to researchers, Microsoft only plugged old holes but missed the evolution of the attack. The ShieldBreak exploit uses a bypass mechanism for these fixes and works with a 100% success rate.
The vulnerability affects the following operating system versions:
- Windows 11 25H2
- Canary channel of Windows 11
- Windows Server 2025
How to protect yourself until an official patch is released?
Currently, there is no official fix for ShieldBreak. Since the attack requires direct access to hardware, it poses the greatest danger to corporate networks and users in public environments. The risk for average home users being targeted is significantly lower.
According to Malwarebytes, the only way to protect yourself at this moment is to disable the built-in antivirus Windows Defender. However, this creates a security gap if an alternative solution is not installed. As a temporary measure, experts recommend using third-party antivirus software, such as Malwarebytes Premium Security.
If Microsoft releases a fix within a month, users of Malwarebytes Premium Security can get a 30-day free protection period if they haven't used this bonus yet.