- Description
- Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
- Source
- secure@microsoft.com
- NVD status
- Modified
- Products
- malware_protection_engine
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- nvd@nist.gov
- NVD-CWE-noinfo
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-269
- Hype score
- Not currently trending
🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG h
@CERT_UG
19 Aug 2026
78 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft is racing to patch "ShieldBreak" (CVE-2026-69414), a Defender zero-day letting local attackers reach SYSTEM privileges on fully patched Windows 10/11 25H2 and Server 2025. PoC is public; no fix yet. https://t.co/0AqEC1bzbE
@ianbishop2021
17 Aug 2026
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:malware_protection_engine:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1CF44512-0B67-4B5F-B271-C8CA45D30DA8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]