TL;DR
A researcher has published a public PoC called ShieldBreak. It bypasses Microsoft’s July patch for the RoguePlanet Windows Defender flaw, CVE-2026-50656. The exploit escalates a standard user to SYSTEM and claims a 100 percent success rate.
- CVE: CVE-2026-50656
- CVSS: 7.8 (High · CVSSv3)
- Product: Microsoft Malware Protection Engine
- Affected: 1.1.0.0
- Impact: Microsoft Defender Elevation of Privilege Vulnerability
- Status: No confirmed exploitation yet
- Patched in: 1.1.26060.3008
- EPSS: 10.7% (30-day)
- Action: Update to 1.1.26060.3008 now
Why it matters
This Windows Defender privilege escalation turns a trusted security tool into an attack path. Microsoft patched the original flaw in July. However, the researcher known as Nightmare Eclipse says that fix failed.
Now ShieldBreak revives the bug with full public exploit code on GitHub. As a result, any attacker with a foothold can reach SYSTEM. That is the highest privilege level on Windows.
How the attack works
CVE-2026-50656 is a race condition in the Microsoft Malware Protection Engine. The engine, mpengine.dll, powers Defender scanning. RoguePlanet abused that race to spawn a SYSTEM shell.
According to the researcher, the patch did not fully close the flaw. Therefore, ShieldBreak reaches the same code path and completes the Windows Defender privilege escalation. The published ShieldBreak proof-of-concept on GitHub documents the bypass in detail.
Affected versions
The researcher tested ShieldBreak on Windows 11 25H2, including the Canary channel, and on Windows Server 2025. Windows 10 and its server editions are also described as vulnerable, though the PoC does not yet support them.
Exploitation status
A public proof-of-concept exists and is confirmed by the researcher’s own release. No in-the-wild exploitation has been confirmed at this time.
Mitigation steps
Confirm that your Malware Protection Engine is current. Microsoft ships engine updates automatically. Still, admins should verify the deployed engine version across managed endpoints.
Watch for a follow-up fix from Microsoft. Meanwhile, limit local access and monitor hosts for unexpected SYSTEM shells.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.