Microsoft Defender Zero-Day Gives Attackers Full Control — No Patch Yet
A security researcher has published a working exploit called ‘ShieldBreak’ that abuses Microsoft Defender to give an attacker full SYSTEM privileges on fully patched Windows 10, Windows 11 and Windows Server machines. Microsoft has confirmed it’s investigating but hasn’t released a fix.
This one matters because Defender isn’t some optional add-on — it’s the default antivirus on virtually every Windows PC sold in Australia. If your business runs Windows (and you almost certainly do), the software that’s supposed to protect you is now the attack surface. ShieldBreak bypasses a patch Microsoft shipped in July for a related flaw called RoguePlanet, meaning even organisations that stayed on top of last month’s updates are exposed. Security researchers have independently confirmed the exploit works with a 100% success rate. We manage Defender across hundreds of endpoints for Australian businesses, and this is the kind of flaw that keeps us watching — when the security tool itself becomes the entry point, layered defences aren’t optional.
What to do right now: Don’t disable Defender — you’d lose more protection than you gain. Instead, make sure your environment has layered security: endpoint detection and response (EDR) tools, application whitelisting, and network segmentation all reduce the blast radius if Defender is bypassed. Limit local admin rights so privilege escalation has fewer places to go. And watch for Microsoft’s patch — when it drops, apply it immediately.
If you’re unsure whether your current setup would catch this kind of exploit, talk to our cybersecurity team about a security review. Layered protection is what turns a zero-day from a crisis into a contained event.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
