Skip to content
feed: live
>_0dayNews
microsoft

ShieldBreak: New Unpatched EoP in Defender Scan Engine

CVE-2026-69414 is a second ShieldBreak-tagged EoP — this one in Defender's Malware Protection Engine, CVSS 7.8. No patch yet. MSRC advisory is live.

ShieldBreak: New Unpatched EoP in Defender Scan Engine
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

A second CVE tagged “ShieldBreak” landed in MSRC’s advisory database on August 14: CVE-2026-69414, rated High, CVSS 7.8. This one is in the Malware Protection Engine — the scanning core, MsMpEng.exe. There is no patch.

This is not the same issue as CVE-2026-50656, which shipped as a fix in August’s Patch Tuesday and had a bypass published the following day. Two separate CVEs, both labeled “ShieldBreak,” both in Defender’s internals, four days apart.

What it is

CVE-2026-69414 is an elevation of privilege vulnerability in the Malware Protection Engine. MsMpEng.exe runs as SYSTEM on Windows machines with Defender’s real-time protection active — it has to, because scanning files and processes at that depth requires elevated access. An EoP flaw here means a path from lower-privilege code execution to full SYSTEM access.

MSRC’s advisory holds technical specifics while a fix is in development. What’s disclosed: the affected component (Malware Protection Engine), the severity (High, CVSS 7.8), and current status (no patch, security update in progress). Microsoft describes the vulnerability as “ShieldBreak,” using the same name that attached to CVE-2026-50656.

What isn’t confirmed

Active exploitation: not confirmed. In-the-wild use: not confirmed. Public proof-of-concept: none observed as of this writing. CISA has not added CVE-2026-69414 to the Known Exploited Vulnerabilities catalog.

Analysis: The prior ShieldBreak bypass (CVE-2026-50656) surfaced within hours of Patch Tuesday. Lazarus exploited CVE-2026-68820 before it was publicly disclosed. Neither of these is evidence that CVE-2026-69414 is currently exploited — but both illustrate that named, actively-researched vulnerabilities in Defender’s internals have historically had short timelines from disclosure to exploitation. Watch the advisory; adjust urgency if that status changes.

Action items

Before the patch:

  • Keep Defender’s Security Intelligence updates current. Microsoft ships signature database updates continuously and independently of Windows Update. These can carry behavioral mitigations ahead of a binary patch. Running outdated definitions leaves an unprotected engine exposed.
  • Watch MSRC’s advisory directly — it will be updated when a fix is available.
  • Review any group policies in your environment that delay or restrict Defender updates. A stability-motivated delay policy works against you when the scanning engine carries a known-unpatched EoP.

When the patch lands:

Push it the same day. CVSS 7.8 on a SYSTEM-privileged process, in a component with an active research community targeting it, warrants immediate application. The prior ShieldBreak bypass demonstrated that window can be hours.

Priority call

Not an emergency today — no confirmed exploitation, no public PoC. Monitor the advisory and keep signatures current. When the patch ships, treat it as immediate. If CISA adds it to KEV before that, escalate accordingly.

Related CVEs
  • [ HIGH ]CVE-2026-69414Elevation of Privilege in Microsoft Defender Malware Protection Engine

Found this useful? Share it.