HomeMalware & ThreatsMicrosoft Encounters New Challenges with Eclipse Zero-Day Vulnerability

Microsoft Encounters New Challenges with Eclipse Zero-Day Vulnerability

Published on

spot_img

Governance & Risk Management,
Patch Management

Attack Manipulates Defender Cloud Hydration to Install an Attacker DLL

Microsoft Encounters New Challenges with Eclipse Zero-Day Vulnerability
Image: Shutterstock

A recent security revelation highlighted a zero-day vulnerability affecting Windows Defender, reported by a researcher known as Nightmare Eclipse. This was disclosed on Patch Tuesday—an occasion on which Microsoft typically issues scheduled updates and security patches for its products. The flaw identified is a privilege-escalation vulnerability that permits low-privileged attackers to gain control at the system level by exploiting the powerful scanning capabilities of the built-in antivirus tool.

This vulnerability, referred to as ShieldBreak, leverages a user-mode callback mechanism. This mechanism essentially allows the kernel of Windows to execute instructions that manipulate user-mode processes while Windows Defender is actively scanning files during its cloud hydration process, under the auspices of the Cloud Filter API. Cybersecurity expert Kevin Beaumont validated this proof-of-concept and provided insights into the seriousness of the threat.

In a statement to ISMG, a Microsoft spokesperson confirmed awareness of the issue and indicated that the company is thoroughly investigating the reported vulnerability to assess its validity and potential implications.

The findings by Beaumont align with an earlier analysis conducted by Will Dormann, a vulnerability analyst at the CERT Coordination Center. Dormann successfully reproduced the exploit by first creating a temporary directory that was registered as a cloud-sync provider, then placing an EICAR test file in that directory to trigger Microsoft Defender’s scanning feature. During this scanning process, the exploit manipulates Defender’s cloud hydration mechanism by utilizing Windows’ Common Log File System and path manipulation tactics to switch the file’s identity and hydration data.

This sophisticated attack results in the placement of a malicious file named phoneinfo.dll within the C:WindowsSystem32 directory, which is a critical folder containing essential Windows system files, executables, dynamic link libraries (DLLs), drivers, and various configuration components.

Once this exploit is executed, it activates the privileged QueueReporting scheduled task used by Windows Error Reporting. This task, which induces the operation of wermgr.exe at elevated privileges, can bypass User Account Control (UAC) and modify sensitive system-level files.

Dormann elaborated on the implications of this exploit, noting that “in the wer.dll code, there is explicit code to load phoneinfo.dll.” With this malicious file in place, it runs with SYSTEM privileges and spawns an instance of conhost.exe.

Interestingly, Nightmare Eclipse has positioned the ShieldBreak vulnerability as a potential bypass of an earlier vulnerability known as RoguePlanet, highlighted in advisory CVE-2026-50656. However, Dormann pointed out that the two vulnerabilities do not appear to share significant similarities, stating, “I don’t recall RoguePlanet doing anything with cloud providers, CLFS, hydration, anything, phoneinfo.dll, and unlike RoguePlanet, ShieldBreak seems to require Defender to be active to work.”

Microsoft has reiterated its commitment to coordinated vulnerability disclosure through its statements regarding the ShieldBreak flaw and promised to implement patches to resolve the issue swiftly. In response to Microsoft’s communications, Nightmare Eclipse criticized the corporation, asserting that it has portrayed the researcher as an “insane criminal” rather than acknowledging the significance of the findings.

In further assertions, the researcher revealed a “major oversight” in Microsoft’s mitigations for a win32k vulnerability exploited by the infamous Stuxnet worm, which was officially assigned CVE-2010-2743 in 2011. This vulnerability allegedly enables attackers to conceal malicious keyboard-layout files within trusted Windows directories, leading the system to accept these files as safe and load them with kernel privileges.

Out of caution, Eclipse chose not to share a proof-of-concept (PoC) for the current vulnerability, citing concerns about potential repercussions and the expectation that Microsoft would patch the exploit vector first.

In conjunction with the discussed vulnerabilities, Microsoft also rolled out fixes for 419 additional vulnerabilities during this month’s Patch Tuesday, following substantial patch releases in previous months—206 in June and a record 622 in July. With these updates, Microsoft aims to address as many security concerns as possible, countering vulnerabilities that threaten user safety.

Adam Barnett, Principal Engineer at security firm Rapid7, reflected on the ongoing challenges posed by the rising volume of vulnerabilities. He noted, “While the Nightmare Eclipse saga is no doubt providing an ongoing headache for MSRC, the increase in vulnerability volume may well be the bigger challenge.” This situation presents Microsoft with an opportunity to reaffirm its dedication to customer security and robust response protocols.

Interestingly, despite earlier tensions, Eclipse has resurfaced on GitHub, utilizing a new account to host previous disclosures. However, a noticeable absence of direct communication with Microsoft has persisted, with the researcher expressing frustration at being “ghosted” by the company, even after making inquiry attempts. Echoing this sentiment, Barnett acknowledged that “no one needs Microsoft’s consent to disclose a vulnerability in a Microsoft product,” stressing the importance of collaboration between security researchers and corporations to effectively manage and mitigate vulnerabilities.

Source link

Latest articles

VINclarity Releases Findings on Alleged Scam and Fraud Reputation Attack Targeting Search and AI

Selidan, USA, August 14th, 2026, CyberNewswire A recent report by VINclarity has shed light on...

Trump Approves Private Sector Involvement in Offensive Cyber Operations

The White House has made a significant policy shift, authorizing federal law enforcement agencies...

Laundry Bear Uses Zimbra Zero-Click Vulnerability to Steal 90 Days’ Worth of Emails

Russian Hacking Campaign Unveiled: A Wake-Up Call for Cybersecurity A recent warning issued by the...

How CSOs Can Transform Cybersecurity into a Business Growth Strategy

Integrating Security into Business Operations: A Strategic Approach In today's rapidly evolving technological landscape, it...

More like this

VINclarity Releases Findings on Alleged Scam and Fraud Reputation Attack Targeting Search and AI

Selidan, USA, August 14th, 2026, CyberNewswire A recent report by VINclarity has shed light on...

Trump Approves Private Sector Involvement in Offensive Cyber Operations

The White House has made a significant policy shift, authorizing federal law enforcement agencies...

Laundry Bear Uses Zimbra Zero-Click Vulnerability to Steal 90 Days’ Worth of Emails

Russian Hacking Campaign Unveiled: A Wake-Up Call for Cybersecurity A recent warning issued by the...