Researcher Defies Microsoft Legal Threat, Drops Unpatched Windows Defender Exploit
Windows, WindA security researcher has publicly released an unpatched Windows exploit dubbed “nasty” by observers, openly defying Microsoft after the Company threatened legal action against researchers who disclose bugs outside its rules.
The researcher, known as Nightmare Eclipse, has published a proof-of-concept for ShieldBreak, a flaw targeting Windows Defender, the anti-malware engine built into every copy of Windows.
Successfully exploited, ShieldBreak lets an attacker escalate from a low-level user account to full system access, effectively handing over the keys to the entire machine.
The exploit affects Windows 10, Windows 11 and Windows Server 2025, according to the researcher. Fellow security researcher Will Dormann has confirmed the bug works.
The proof of concept was released as a downloadable Windows app, meaning a target would need to run it for the exploit to fire.
No patch exists. Microsoft says it is “aware of the reported vulnerability and is actively investigating.”
Feud Boils Over
The release is the latest salvo in a long-running feud between Nightmare Eclipse and Microsoft over how the Company handles bug reports, with the researcher accusing Microsoft of mishandling previous disclosures, resulting in several bugs being published publicly rather than quietly patched.
ShieldBreak reportedly builds on an earlier exploit from the same researcher, RoguePlanet. Microsoft patched that flaw, but Nightmare Eclipse claims the fix fell short and that ShieldBreak fully bypasses it.
In May, Microsoft inflamed tensions by threatening legal action against researchers who go public with zero-days outside its disclosure rules. The security community pushed back hard, and Microsoft softened its stance on social media, though the original blog post remains live.
Vulnerabilities Double As Prices Rise
The disclosure lands as Microsoft battles a bug infestation across multiple products while simultaneously raising prices for both B2B and consumer software.
Total Microsoft critical vulnerabilities have doubled to 157, reversing more than a decade of steady improvement, according to BeyondTrust’s annual report.
Windows accounted for 612 CVEs and Windows Server 780, remaining the largest sources of vulnerabilities. Azure and Dynamics 365 vulnerabilities plateaued at 69 in 2025, but critical flaws hit a record high, jumping from 4 to 37, a 9x surge.
Elevation of Privilege flaws, the same class as ShieldBreak, made up 40% of all 2025 vulnerabilities, giving attackers a fast path from a foothold to full control, analysts claim.
Patch Tuesdays have ballooned in 2026. July’s update alone addressed 622 vulnerabilities across Windows, Office, SharePoint Server, AD FS, Exchange, Azure components and SQL Server, including two flaws actively exploited in the wild, an AD FS privilege escalation (CVE-2026-56155) and a SharePoint Server privilege escalation (CVE-2026-56164).
The SharePoint bug was particularly nasty, remotely exploitable without authentication and raising the risk to internet-facing servers.
Three Converging Pressures
Microsoft is facing an identity-centric threat model, with state-sponsored attacks now targeting credentials rather than just zero-days and more password spraying and token theft expected.
AI is cutting both ways, accelerating vulnerability discovery for defenders and attackers alike and shrinking the gap between disclosure and exploitation.
The Company is also under ongoing reputational and regulatory heat from governments after repeated federal-system compromises.
In response, Microsoft has moved every Microsoft Account and Entra ID token-signing key into hardware security modules or Azure confidential VMs with automatic rotation under its Secure Future Initiative, an implicit admission of the key-management failures behind the Storm-0558 debacle.
For Windows users, with no ShieldBreak patch available, this is one to watch.











































































