Оксана СтепураHot News
13 August 2026, 17:02
2026-08-13
A researcher has found a vulnerability in Microsoft Defender that allows a system file to be replaced. How does it work?
A cybersecurity researcher using the pseudonym Nightmare Eclipse has published a new vulnerability in Windows that could allow an attacker to gain elevated system privileges on a computer. It's called ShieldBreak and exploits Windows' built-in Microsoft Defender antivirus. Microsoft has yet to release a patch and said it's investigating the bug.
A cybersecurity researcher using the pseudonym Nightmare Eclipse has published a new vulnerability in Windows that could allow an attacker to gain elevated system privileges on a computer. It's called ShieldBreak and exploits Windows' built-in Microsoft Defender antivirus. Microsoft has yet to release a patch and said it's investigating the bug.
The researcher published a test application that actually exploits the vulnerability and gains the highest privileges in Windows. It itself is designed to demonstrate the bug, but the same mechanism can be built into a malicious program.
ThreatLocker explained how this vulnerability works. So, the attacker must force the user to download and run a malicious file. And this malicious file will create a decoy file, with a design similar to a file from cloud storage. That is, the system sees it, but will load the contents only when some program tries to open it. This file will be perceived by the antivirus as a potential threat.
And here is where the substitution happens. While Defender is loading the file, ShieldBreak changes both its contents and the place where this content should go, and redirects the antivirus's operation path from the decoy location to the system file. After processing the file, Defender usually overwrites the files. As a result, instead of the decoy file, the antivirus writes a DLL with malicious code to the system file, not noticing the substitution. So the attacker's code acquires administrator rights.
According to Nightmare Eclipse, ShieldBreak affects Windows 11 and Windows 10.
In recent months, the researcher has published several unpatched Windows vulnerabilities at once. He accused Microsoft of doing a poor job with bug reports and claimed that the company effectively left him no other way to draw attention to the problems.
In May, Microsoft strongly criticized the publication of such vulnerabilities without prior notice to the developer and mentioned the possibility of legal prosecution for those who facilitate criminal activity. But after a wave of criticism, the company clarified its position and said that it would not prosecute people simply for conducting or publishing legitimate cybersecurity research.
Previously, dev.ua wrote about a bug that allowed attackers to gain access to someone else's computer through Zoom.
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Що, юний хакер, тобі цікаво, які ігри ще досі не крякнули? Тоді мерщій читай цю статтю. Нижче ми розглянемо, які технології використовуються для захисту ігор від злому. Також не пройдемо повз рекордсменів. Дізнаємося про рекордний час, за який вдалося зламати гру. Та розглянемо справжніх «міцних горішків».