< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Cybersecurity researchers identify privilege escalation flaws in Kaspersky and Microsoft Defender

New cybersecurity research has identified potential privilege escalation vulnerabilities affecting Windows 11 and Windows Server 2025 environments through both security software and native Microsoft tools.

A researcher known as MSNightmare has published a proof of concept (PoC) for an alleged zero-day vulnerability in Kaspersky Endpoint Security. The claim suggests that a local user could exploit a flaw in a user-interface process to gain unauthorized permissions, potentially allowing the creation of files within the protected System32 directory. Kaspersky has not yet publicly confirmed the issue or assigned a CVE.

Separately, a public exploit named ‘ShieldBreak’ has been identified, which targets Microsoft’s Windows Defender. The exploit reportedly bypasses a July patch for a previous vulnerability (CVE-2026-50656) by using the Cloud Filter API and CLFS log manipulation to turn the security tool itself into an escalation mechanism. This chain, identified as CVE-2026-69414, allows an attacker with a local foothold to gain SYSTEM-level access. Microsoft is currently investigating the matter.

Entities

Kaspersky · Microsoft · Windows 11 · Windows Defender