Home » After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug

After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug

by Brandon Duncan


A security researcher has published details of a new vulnerability in the latest versions of Windows that allows hackers to gain system-wide access to the user’s device and data, despite facing a legal threat from Microsoft weeks earlier over the release of previously unknown software flaws.

The new bug, dubbed ShieldBreak, is the latest disclosure by security researcher Nightmare Eclipse, who in recent months has published details of several bugs affecting Microsoft’s products, including Windows.

According to Nightmare Eclipse’s post, ShieldBreak takes advantage of a flaw in Windows Defender, the anti-malware and security engine built into Windows. A successful attack allows the hacker to escalate their permissions from a low-level user to full access to the device and its data. 

Nightmare Eclipse published the proof-of-concept exploit as a Windows app, requiring the user to run the app to exploit the bug. The bug works on Windows 10, Windows 11 (including the latest 25H2 version), and Windows Server 2025, the researcher said.

Security researcher Will Dormann verified that the bug works and that Windows Defender must be enabled for the exploit to work. 

The latest exploit builds on an earlier exploit that Nightmare Eclipse developed dubbed RoguePlanet, according to Nightmare Eclipse. Microsoft rolled out a patch for RoguePlanet, but the researcher implied that Microsoft’s fix was not sufficient and that their latest exploit demonstrates a full bypass of the earlier patch.

Microsoft has not yet released a patch for the ShieldBreak bug. A spokesperson for Microsoft did not immediately comment when contacted by TechCrunch. The bug is considered a zero-day because the software maker — in this case, Microsoft — was given no time to patch the bug before it was publicly disclosed.

The release of this new zero-day is the latest in a long back-and-forth between the security researcher and the software giant over the company’s alleged handling of their bug reports. 

In a series of blog posts, the security researcher claimed that Microsoft mistreated them and did not handle their bug reports sufficiently, with the implication that the researcher had no other choice but to publicly disclose the bugs online. Nightmare Eclipse previously released several other bugs in Windows that were later exploited in real-world attacks to hack into organizations.

In May, Microsoft published a blog post threatening to take legal action against security researchers, like Nightmare Eclipse, if they released details of zero-days outside of the company’s disclosure policies. The company faced heavy rebuke from the security community, many of whom described similar experiences with Microsoft’s handling of their bug reports. Microsoft later walked back the comments in a social media post. Its original blog post remains published and unchanged.

ShieldBreak lands a day after Microsoft’s regularly scheduled monthly security patch releases, dubbed Patch Tuesday. This is the second month in a row where the number of patches has reached around 500 or so bugs driven by the company’s growing use of AI to find and weed out security flaws.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

You may also like

Leave a Comment