Governance & Threat Administration
,
Patch Administration
Assault Manipulates Defender Cloud Hydration to Set up an Attacker DLL

The researcher on a Microsoft bug discovery spree once more revealed a zero-day on Patch Tuesday, a privilege-escalation flaw in Home windows Defender.
See Additionally: The Finish of Believable Deniability: Information Privateness Compliance in 2026
The brand new vulnerability, dubbed ShieldBreak by the researcher utilizing the deal with Nightmare Eclipse, permits a low-privileged attacker to realize system-level management by exploiting the built-in antivirus software’s privileged scanning capabilities to execute malicious code.
It makes use of a user-mode callback, a mechanism permitting the kernel to execute directions again into user-mode, to vary a file’s content material whereas Home windows Defender is scanning it throughout cloud hydration by means of the Cloud Filter API, mentioned cybersecurity researcher Kevin Beaumont after verifying the proof-of-concept.
“Microsoft is conscious of the reported vulnerability and is actively investigating the validity and potential applicability of those claims,” a Microsoft spokesperson advised ISMG.
Beaumont’s discovering echoes that from CERT Coordination Heart’s vulnerability analyst Will Dormann, who reproduced the exploit. Dormann started with creating a short lived listing registered as a cloud-sync supplier and inserting an EICAR take a look at file there to set off Microsoft Defender scanning. Throughout the scan, ShieldBreak manipulates Defender’s cloud-hydration course of, utilizing mechanisms in a Home windows logging subsystem for software program functions known as Frequent Log File System and path manipulation to swap file id and hydration information.
Consequently, an attacker-controlled phoneinfo.dll is positioned in C:WindowsSystem32, Dormann mentioned, which is a folder containing core Home windows system information, executables, Dynamic Hyperlink Libraries, drivers and configuration-related parts.
The exploit then triggers the privileged QueueReporting scheduled process utilized by Home windows Error Reporting, which runs wermgr.exe –add with highest privileges, which means it might probably bypass Person Account Management and modify System-level information.
“Within the wer.dll code, there may be express code to load phoneinfo.dll,” Dormann mentioned. “As a result of at this level, phoneinfo.dll exists and is our personal code, this runs, spawning conhost.exe with SYSTEM privileges.”
Though Nightmare Eclipse claimed the brand new flaw is a patch bypass of the beforehand reported RoguePlanet vulnerability – CVE-2026-50656 – Dormann mentioned the 2 do not appear to share similarities.
“I do not recall RoguePlanet doing something with cloud suppliers, CLFS, hydration something, phoneinfo.dll, and in contrast to RoguePlanet, ShieldBreak appears to require Defender to be energetic to work,” Dormann mentioned.
Microsoft re-emphasized coordinated vulnerability disclosure in its assertion for ShieldBreak and promised to patch impacted merchandise as quickly as doable. Nightmare Eclipse responded Friday, telling the corporate to “reduce the crap” and that it’s “attempting onerous to color [Eclipse] as some insane legal.”
The pseudonymous researcher additionally claimed to have discovered a “main oversight” in Microsoft’s mitigations for the win32k vulnerability exploited by the Stuxnet worm, assigned CVE-2010-2743 in 2011, which might depart a associated assault path exploitable.
The flaw allegedly permits an attacker to cover a malicious keyboard-layout file inside a trusted Home windows folder, inflicting the system to deal with it as secure and cargo it with kernel privileges.
Eclipse mentioned they determined to not roll out the PoC on this case as a result of they could get into hassle, and the approach to learn the file will get patched.
On the similar time, Microsoft launched fixes for 419 vulnerabilities on this month’s Patch Tuesday, following 206 patches in June and a file of 622 in July. The August updates embrace a repair for LegacyHive, which Eclipse disclosed simply hours after July’s Patch Tuesday launch.
“Whereas the Nightmare Eclipse saga is little doubt offering an ongoing headache for MSRC, the rise in vulnerability quantity might be the larger problem,” Principal Engineer Adam Barnett at safety agency Rapid7 advised ISMG. “The continued turbulence is a chance for Microsoft to lean into established process and reaffirm their dedication to clients and the broader group.”
Eclipse has returned to Microsoft-owned GitHub since their earlier exile from the platform, with a brand new account that hosts a few of their beforehand disclosed bugs – however there seems to be no direct communication between the 2 events.
“Microsoft simply refuses any type of communication, all the time ghosting me even after I ask for something,” Eclipse mentioned. “I can not even report the bugs I discover to their respective distributors due to the restrictions by Microsoft… Assume I’ll begin publishing bugs for third events in that window the place Patch Tuesday is not launched but.”
The safety group has usually seen Microsoft’s position within the battle with skepticism. “Nobody wants Microsoft’s consent to reveal a vulnerability in a Microsoft product,” Barnett mentioned. “Microsoft’s finest pursuits are served by sustaining cordial relationships with safety researchers.”









