Another Patch Tuesday, Another Nightmare Eclipse Zero-Day
ShieldBreak is the 10th zero-day vulnerability which Nightmare Eclipse has posted to GitHub. These releases are not good for sysdamin’s blood pressure and Microsoft is livid that this person or group refuses to follow their vulnerability disclosure rules but they are certainly effective at getting attention. The story is that Nightmare Eclipse did have a relationship with Microsoft and was following proper procedures until Microsoft reneged on the deal without warning. Microsoft intended legal action against Nightmare Eclipse, and if Microsoft does know who they are then that could have proceeded. However the majority of professional security experts suggested that was an idiotic idea as the vulnerabilities would still exist and if they were never published then they could never be patched.
That all leads to the 10th vulnerability, ShieldBreak, a script which grants SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. Researchers have run the local privilege-escalation exploit script on a Windows 11 25h2 machine getting updates from the Canary channel and windows server 2025, with a 100% success rate. Windows 10 not so much, but that’s not because it is immune, it’s just that the script needs some polishing to work perfectly on the older machines.