Bypass Record
Exploitation for Priv-Esc × Microsoft Windows Defender
A publicly-reported instance of Exploitation for Priv-Esc bypassing Microsoft Windows Defender, recorded with its original source. Factual record; no assessment of any specific deployment.
Mechanism
ShieldBreak exploits a vulnerability in Windows Defender's file scanning mechanism. By crafting a malicious file that triggers a race condition or improper handling during scanning, the exploit bypasses the patch and achieves arbitrary code execution with SYSTEM privileges. It defeats the security agent's own protections and the applied patch.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.