Patching a vulnerability is supposed to close the door. Sometimes it only moves the lock.
The bug we already told you to fix is back
Back in June we covered RoguePlanet, a Windows Defender privilege escalation flaw that let a local attacker with a foothold work their way up to SYSTEM. Microsoft shipped a fix for it in the Defender Malware Protection Engine in July. Any team that applied that update reasonably assumed the issue was closed. It was not. A researcher going by Nightmare Eclipse, the same person credited with finding RoguePlanet, has now published a proof of concept called ShieldBreak that reaches SYSTEM through a different exploitation path Microsoft’s July patch never touched.
From unreliable to guaranteed
RoguePlanet was a race condition, which meant it worked sometimes and failed sometimes, the kind of bug that is real but hard to weaponise at scale. ShieldBreak is not that. Testing against Windows 11 version 25H2, Windows Insider Canary builds and Windows Server 2025 reportedly produced a 100 percent success rate for local privilege escalation. Microsoft has assigned it CVE-2026-69414 with a CVSS score of 7.8 and an exploitability rating of “Exploitation More Likely,” which is Microsoft’s own language for telling defenders this is not a theoretical risk.
No patch, no workaround, no affected-build list
As of this writing Microsoft has not shipped a fix, published a workaround, or even confirmed a definitive list of affected builds. That leaves security teams in an uncomfortable position: the vendor has confirmed the flaw is real and likely to be exploited, but has given no timeline and no interim mitigation to point to. Endpoint detection tuned to catch privilege escalation behaviour, not just known exploit signatures, is the only real lever available until a patch lands. Machines that already received July’s RoguePlanet update should not be treated as protected, because ShieldBreak was built specifically around a path that update does not cover.
Why “we already patched that” is not an answer anymore
This is the second time in two months that a Defender privilege escalation bug from this researcher has forced a re-evaluation of what “patched” actually means. If your patch management process treats a CVE as closed the moment an update ships, without revisiting it when new bypass research appears, ShieldBreak is exactly the kind of gap that process will miss.
If you need help tracking which of your Windows fleets are exposed to ShieldBreak, or want your vulnerability management process rebuilt so bypass research like this does not slip through, contact Excello Digital. We help European organisations turn patch confirmations into actual verified protection.
