After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug

← Back to the feed

After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug

TechCrunch · 2 hours ago

A security researcher known as Nightmare Eclipse has publicly disclosed a new Windows zero-day, ShieldBreak, after Microsoft previously threatened legal action over disclosures made outside its reporting policies. The flaw reportedly enables a low-privilege user to obtain full access to a Windows device and its data, increasing the risk for organisations and individuals before an official fix is available.

ShieldBreak exploits Windows Defender and is said to affect Windows 10, Windows 11 including version 25H2, and Windows Server 2025; independent researcher Will Dormann reportedly verified it. The proof-of-concept requires a user to run a malicious app, and the disclosure follows claims that Microsoft’s earlier patch for a related exploit, RoguePlanet, could be bypassed; Microsoft had not issued a ShieldBreak patch at publication.

  • New Windows zero-day reportedly grants system-wide access.
  • It affects Windows Defender-enabled systems, including current Windows versions.
  • Microsoft had not released a patch.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Supporters of publication argue that independent researchers help hold major software companies accountable, particularly when vulnerabilities may otherwise remain unaddressed or their severity understated. They may contend that public disclosure can prompt faster fixes, inform defenders of real risks and protect legitimate security research from legal intimidation, provided the technical details are shared responsibly.

The case against

Critics argue that releasing a Windows zero-day before a patch is available can expose ordinary users, businesses and public services to avoidable exploitation. They may favour coordinated disclosure with Microsoft, maintaining that legal or contractual safeguards can be justified where publication risks turning a research finding into a practical tool for criminals.

Business Markets

Read the full article at the source →