Головні звуки українського ІТ. Вгадаєш всі? 👉

A researcher has found a vulnerability in Microsoft Defender that allows a system file to be replaced. How does it work?

A cybersecurity researcher using the pseudonym Nightmare Eclipse has published a new vulnerability in Windows that could allow an attacker to gain elevated system privileges on a computer. It's called ShieldBreak and exploits Windows' built-in Microsoft Defender antivirus. Microsoft has yet to release a patch and said it's investigating the bug.

Leave a comment
A researcher has found a vulnerability in Microsoft Defender that allows a system file to be replaced. How does it work?

A cybersecurity researcher using the pseudonym Nightmare Eclipse has published a new vulnerability in Windows that could allow an attacker to gain elevated system privileges on a computer. It's called ShieldBreak and exploits Windows' built-in Microsoft Defender antivirus. Microsoft has yet to release a patch and said it's investigating the bug.

This was reported by TechCrunch.

The researcher published a test application that actually exploits the vulnerability and gains the highest privileges in Windows. It itself is designed to demonstrate the bug, but the same mechanism can be built into a malicious program.

ThreatLocker explained how this vulnerability works. So, the attacker must force the user to download and run a malicious file. And this malicious file will create a decoy file, with a design similar to a file from cloud storage. That is, the system sees it, but will load the contents only when some program tries to open it. This file will be perceived by the antivirus as a potential threat.

And here is where the substitution happens. While Defender is loading the file, ShieldBreak changes both its contents and the place where this content should go, and redirects the antivirus's operation path from the decoy location to the system file. After processing the file, Defender usually overwrites the files. As a result, instead of the decoy file, the antivirus writes a DLL with malicious code to the system file, not noticing the substitution. So the attacker's code acquires administrator rights.

According to Nightmare Eclipse, ShieldBreak affects Windows 11 and Windows 10.

In recent months, the researcher has published several unpatched Windows vulnerabilities at once. He accused Microsoft of doing a poor job with bug reports and claimed that the company effectively left him no other way to draw attention to the problems.

In May, Microsoft strongly criticized the publication of such vulnerabilities without prior notice to the developer and mentioned the possibility of legal prosecution for those who facilitate criminal activity. But after a wave of criticism, the company clarified its position and said that it would not prosecute people simply for conducting or publishing legitimate cybersecurity research.

Previously, dev.ua wrote about a bug that allowed attackers to gain access to someone else's computer through Zoom.

Why did OpenAI create an AI that can create exploits? OpenAI presents GPT-5.6-Cyber
Why did OpenAI create an AI that can create exploits? OpenAI presents GPT-5.6-Cyber
On the topic
Why did OpenAI create an AI that can create exploits? OpenAI presents GPT-5.6-Cyber
Hackers may have hacked the CPUID website and replaced the installers of the popular programs HWMonitor and CPU-Z
Hackers may have hacked the CPUID website and replaced the installers of the popular programs HWMonitor and CPU-Z
On the topic
Hackers may have hacked the CPUID website and replaced the installers of the popular programs HWMonitor and CPU-Z
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Also Read
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Що, юний хакер, тобі цікаво, які ігри ще досі не крякнули? Тоді мерщій читай цю статтю. Нижче ми розглянемо, які технології використовуються для захисту ігор від злому. Також не пройдемо повз рекордсменів. Дізнаємося про рекордний час, за який вдалося зламати гру. Та розглянемо справжніх «міцних горішків».
6
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
4 comments
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
4 comments
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
3 comments

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.