started · updated
Windows vulnerabilities ShieldBreak and Plug and Pwn allow privilege escalation
Security researchers have identified two significant Windows vulnerabilities that allow for privilege escalation to the SYSTEM level.
The first vulnerability, named ‘ShieldBreak’, was discovered by researcher Nightmare Eclipse. It targets Windows 10, Windows 11, and Windows Server 2025. The exploit reportedly bypasses previous fixes related to the ‘RoguePlanet’ vulnerability by leveraging a user-mode callback hook to modify file contents during a Microsoft Defender cloud-hydration scan via the Cloud Filter API. Experts Kevin Beaumont and Will Dormann have confirmed the exploit, noting that Microsoft Defender must be active for the attack to function.
The second vulnerability, dubbed ‘Plug and Pwn’, was presented at DEF CON 34 by Alejandro Hernando and Borja Martinez. This flaw targets how Windows identifies USB devices and installs drivers. An attacker can emulate a USB device to trick Windows into installing malicious vendor packages with Authority/System privileges.
While Microsoft has released detection signatures via Windows Defender, many systems remain at risk if they have not applied the latest cumulative updates.
Entities
Microsoft · Microsoft Defender · Nightmare Eclipse · Windows