Microsoft Defender contains ShieldBreak zero-day vulnerability, fix underway
Microsoft has acknowledged a zero-day vulnerability in its Microsoft Defender antimalware software, dubbed ShieldBreak. The flaw could allow an attacker to gain SYSTEM privileges on a Windows device.

Microsoft has confirmed a zero-day vulnerability in its Microsoft Defender antimalware software, identified as ShieldBreak. Security researchers disclosed the flaw, which could escalate privileges for any Windows user account to SYSTEM level, granting complete control over the affected device.
The company stated that the issue lies within the Microsoft Malware Protection Engine used by Defender and that a fix is currently in development. This vulnerability is reportedly linked to a previously patched flaw, Rogue Planet (CVE-2026-50656), with researchers finding the initial fix to be incomplete.
While both ShieldBreak and Rogue Planet target Microsoft Defender, their exploitation methods differ. Rogue Planet involved manipulating file operation paths, whereas ShieldBreak leverages API callback timing during file scans to substitute content. These findings highlight the ongoing challenges in securing software against evolving threats.
Microsoft has indicated its security team is investigating and working to deploy a corrective update. Users are advised to ensure their Defender software remains up-to-date.