decrypted · 22 august 2026 · vulnerabilities and patching · supply chain

The Windows Defender zero-day that beat Microsoft's own patch, and the fix that still isn't here

Microsoft's August Patch Tuesday landed eleven days ago, and Windows Defender, the antivirus running by default on most of the UK's Windows laptops and servers, still has a working bypass sitting in public view. A researcher going by Nightmare Eclipse published a proof of concept called ShieldBreak that grants full SYSTEM access on a completely up to date Windows 11 or Windows Server 2025 machine. It works by beating the patch Microsoft shipped in July for an almost identical flaw. Microsoft's response so far is that it is investigating the validity of the claims. There is no official fix. This is a small, specific bug in one product, but the lesson underneath it, that closing one door in a room with two doors is not the same as fixing the room, is worth ten minutes of any UK security lead's week.

How a fix gets un-fixed

In July, Microsoft patched RoguePlanet, a flaw that let a low privileged user trick Defender into scanning one file and then swap it for a malicious one before Defender finished acting on what it had seen, a classic time of check, time of use race. The fix closed that specific race condition. ShieldBreak, published this month, reaches the same destination by a different corridor. According to researcher Will Dormann's technical breakdown, it plants a harmless test file, uses Windows' own link resolution and logging subsystem to redirect Defender's cloud scan toward a system file that does not normally exist, then lets a routine, highly privileged Windows task load and run it. Defender is not tricked into ignoring a threat. It is tricked into becoming the delivery mechanism. The parcel changes hands after the guard has already stamped it as checked.

The design lesson, not just the patch lesson

The specific bug matters less than what it confirms: Microsoft's July fix addressed one exploitation path through a shared weak point in how Defender's privileged scanning interacts with the filesystem, not the weak point itself. That is a pattern, not a one off: this is the second Defender privilege escalation bypass from the same researcher in as many months, following a public and unusually bitter dispute after Microsoft threatened legal action over an earlier disclosure. For UK organisations, many of which run Defender as their only endpoint control because it is free and built in, the takeaway is not "wait for the patch." It is that a security product's own privileged code path is itself an attack surface, and a "fixed" CVE number is a claim about one exploitation route, not a guarantee about the underlying design. Until Microsoft ships something official, treat unofficial community mitigations circulating for ShieldBreak as unverified, and lean on monitoring for the specific process chain researchers have described, rather than on Defender's SYSTEM level trust alone.

Also this week

The Metabase flaw covered here on 8 August has claimed a very concrete UK victim. Trezor disclosed that ShipMonk, the shipping provider that fulfils its hardware wallet orders, was breached through that same SQL injection bug in Metabase's password reset endpoint. Names, addresses, emails and phone numbers for close to 14,000 customers were exposed, including buyers in the UK, from orders placed between May and August. Trezor's own systems were never touched: the entire exposure sat with a logistics vendor holding months of order data it had no obvious need to keep that long.

Separately, Microsoft's August Patch Tuesday quietly fixed a near maximum severity flaw in Azure Active Directory, now Entra ID, the identity platform behind sign in for most UK Microsoft 365 tenants. CVE-2026-50481, rated 9.9, let a low privileged, already authenticated attacker tamper with data Entra treats as fixed and untouchable, to escalate to elevated network privileges with no user interaction needed. Microsoft has already patched it server side, so there is nothing to deploy, but a bug that severe in the system every other control assumes is trustworthy is a reminder that identity platforms deserve the same scrutiny as anything else, not less because a hyperscaler runs them.

Sources

Working through what any of this means for your own systems? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.