Microsoft has confirmed it is working on a patch for ShieldBreak, a newly disclosed Microsoft Defender zero-day tracked as CVE-2026-69414. The flaw, revealed by Nightmare Eclipse, can let local attackers with limited permissions gain SYSTEM privileges on fully patched Windows systems and is linked to the earlier RoguePlanet issue. #ShieldBreak #CVE-2026-69414 #NightmareEclipse #RoguePlanet
Keypoints
- Microsoft is investigating ShieldBreak and preparing a security update.
- ShieldBreak is a Defender privilege escalation flaw tracked as CVE-2026-69414.
- Nightmare Eclipse published a PoC that can elevate local users to SYSTEM.
- The exploit appears to bypass the earlier RoguePlanet patch.
- Other Nightmare Eclipse disclosures, including LegacyHive and UnDefend, remain unpatched.