preloader

· · digital-security devops microsoft windows windows-defender cve vulnerability-management patch-management zero-day europe

Microsoft’s July Fix for a Windows Defender Bug Did Not Actually Fix It

Source: The Hacker News

Patching a vulnerability is supposed to close the door. Sometimes it only moves the lock.

The bug we already told you to fix is back

Back in June we covered RoguePlanet, a Windows Defender privilege escalation flaw that let a local attacker with a foothold work their way up to SYSTEM. Microsoft shipped a fix for it in the Defender Malware Protection Engine in July. Any team that applied that update reasonably assumed the issue was closed. It was not. A researcher going by Nightmare Eclipse, the same person credited with finding RoguePlanet, has now published a proof of concept called ShieldBreak that reaches SYSTEM through a different exploitation path Microsoft’s July patch never touched.

From unreliable to guaranteed

RoguePlanet was a race condition, which meant it worked sometimes and failed sometimes, the kind of bug that is real but hard to weaponise at scale. ShieldBreak is not that. Testing against Windows 11 version 25H2, Windows Insider Canary builds and Windows Server 2025 reportedly produced a 100 percent success rate for local privilege escalation. Microsoft has assigned it CVE-2026-69414 with a CVSS score of 7.8 and an exploitability rating of “Exploitation More Likely,” which is Microsoft’s own language for telling defenders this is not a theoretical risk.

No patch, no workaround, no affected-build list

As of this writing Microsoft has not shipped a fix, published a workaround, or even confirmed a definitive list of affected builds. That leaves security teams in an uncomfortable position: the vendor has confirmed the flaw is real and likely to be exploited, but has given no timeline and no interim mitigation to point to. Endpoint detection tuned to catch privilege escalation behaviour, not just known exploit signatures, is the only real lever available until a patch lands. Machines that already received July’s RoguePlanet update should not be treated as protected, because ShieldBreak was built specifically around a path that update does not cover.

Why “we already patched that” is not an answer anymore

This is the second time in two months that a Defender privilege escalation bug from this researcher has forced a re-evaluation of what “patched” actually means. If your patch management process treats a CVE as closed the moment an update ships, without revisiting it when new bypass research appears, ShieldBreak is exactly the kind of gap that process will miss.

If you need help tracking which of your Windows fleets are exposed to ShieldBreak, or want your vulnerability management process rebuilt so bypass research like this does not slip through, contact Excello Digital. We help European organisations turn patch confirmations into actual verified protection.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!