> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← Back to Articles

ShieldBreak: Exploiting Windows Defender's Symlink Race Condition

[ View on GitHub ]

ShieldBreak: Exploiting Windows Defender's Symlink Race Condition

Hook

What if Windows Defender itself could be tricked into corrupting your system files? ShieldBreak proves that even after decades of TOCTOU hardening, Microsoft's antivirus engine still falls victim to a 50-millisecond race condition.

Context

Windows Defender's architecture relies on WdFilter, a kernel-mode minifilter driver that intercepts file system operations to scan for malware. When MsMpEng.exe (Defender's scanning engine) examines a suspicious file, it performs multiple operations: opening the file, reading its contents, analyzing behavior, and potentially quarantining threats. Each phase involves separate kernel callbacks and file handle operations.

The challenge for security researchers has always been exploiting the time gap between these operations. Microsoft has spent years hardening these code paths, implementing impersonation-based access checks and attempting to eliminate TOCTOU (time-of-check-time-of-use) vulnerabilities. ShieldBreak demonstrates that despite these efforts, Windows Defender's multi-phase scanning process still contains exploitable race windows—particularly in the remediation phase where Defender acts on files it has already validated. This isn't about evading detection; it's about hijacking Defender's own remediation capabilities to corrupt protected system locations.

Technical Insight

TOCTOU Exploit

Attack Window ~50ms

Triggers scan

Opens file handle

Validates on decoy

Detects handle

NtDeleteSymbolicLinkObject

NtCreateSymbolicLinkObject

Redirects to

No re-validation

Operates on swapped target

Decoy File Creation

MsMpEng.exe Scanner

Permission Check

WdFilter Minifilter

ETW Monitor

Race Loop

Symlink Swap

C:\Windows\System32\drivers

Quarantine/Remediation

System architecture — auto-generated

ShieldBreak's core mechanism exploits the gap between Defender's permission validation and its subsequent file operations during quarantine or remediation. The attack unfolds in three precise stages: decoy creation, symlink racing, and target redirection.

First, the tool creates a benign decoy file designed to trigger Defender's scanning heuristics. This might be a file with suspicious strings, known malware signatures, or behavioral patterns that force MsMpEng.exe to initiate a full scan. The decoy sits at a symlink junction point under the attacker's control—typically in a user-writable directory like %TEMP%.

The critical innovation is timing detection. Rather than blindly racing, ShieldBreak monitors for Defender's scanning activity through ETW (Event Tracing for Windows) or by polling for file handle creation on the decoy. The moment MsMpEng.exe opens the decoy for inspection, a tight polling loop begins:

// Simplified race condition exploit pattern
HANDLE hSymlink = NULL;
UNICODE_STRING symlinkPath, targetPath;

// Monitor for Defender handle acquisition
while (!DefenderHandleDetected()) {
    Sleep(1);
}

// Aggressive symlink swap loop
for (int i = 0; i < 1000; i++) {
    // Delete existing symlink
    NtDeleteSymbolicLinkObject(hSymlink);
    
    // Recreate pointing to system directory
    RtlInitUnicodeString(&targetPath, L"\\??\\C:\\Windows\\System32\\drivers");
    
    OBJECT_ATTRIBUTES objAttr;
    InitializeObjectAttributes(&objAttr, &symlinkPath, 
                               OBJ_CASE_INSENSITIVE, NULL, NULL);
    
    NtCreateSymbolicLinkObject(&hSymlink, SYMBOLIC_LINK_ALL_ACCESS,
                               &objAttr, &targetPath);
    
    // Attempt to catch Defender in quarantine phase
    NtSetInformationFile(hSymlink, &ioStatus, &renameInfo,
                        sizeof(renameInfo), FileRenameInformation);
}

The magic happens when Defender transitions from scanning to remediation. MsMpEng.exe validated permissions on the decoy file—confirming it has rights to quarantine or delete user-owned content. But when it performs the actual remediation operation, it uses a file handle that now resolves through the attacker's symlink to C:\Windows\System32\drivers. Defender's minifilter callbacks don't re-validate the target because they assume the handle context hasn't changed.

This works because of how Windows resolves symbolic links at different layers. The initial access check happens in user mode with impersonation tokens, but the subsequent write operations occur in kernel mode through the filter manager. The minifilter's pre-operation callback sees the original validated path, but the post-operation callback acts on the redirected target. Microsoft's CVE-2026-50656 fix apparently addressed one callback sequence but left others exploitable.

The version specificity (Windows 11 22H2+, Server 2025) suggests ShieldBreak exploits recent refactoring in Defender's codebase. Microsoft added AI-powered scanning features in late 2024 that introduced new code paths for behavioral analysis. These paths likely include additional file operations—more opportunities for TOCTOU windows. The tool targets these newer callback sequences that don't exist in Windows 10's older Defender architecture.

What makes this particularly insidious is the attack vector itself: Defender's own operations appear to corrupt system files. From an EDR perspective, all activity originates from signed Microsoft processes (MsMpEng.exe) acting on legitimate threat detections. The forensic trail shows Defender correctly identifying malware and performing standard remediation—except the remediation accidentally corrupted a driver in System32. This looks like an antivirus bug rather than an active exploit.

Gotcha

The most significant limitation is the Administrator privilege requirement. Creating symbolic links on Windows requires either admin rights or Developer Mode, which dramatically narrows real-world exploitation scenarios. If you already have admin privileges, there are often simpler ways to achieve persistence or defense evasion—why execute a timing-sensitive kernel race when you could just modify registry keys or inject into LSASS?

The version dependency is equally problematic. ShieldBreak explicitly doesn't support Windows 10 despite those systems theoretically having the same vulnerable patterns. This brittleness suggests the exploit relies on exact callback ordering, memory layouts, or API behaviors that change between kernel versions. Any Windows Update that modifies filter manager internals, adjusts MsMpEng.exe scanning heuristics, or changes NTFS reparse point handling could silently break the exploit. The claimed 100% success rate likely assumes controlled lab conditions—identical VM configurations, disabled third-party security software, and specific system load profiles. Production environments with EDR agents, custom minifilters, or heavy I/O activity would introduce variables that could disrupt the precise timing required. Additionally, this provides no privilege escalation path; it's purely a post-exploitation primitive for attackers who have already compromised a system at admin level and want to degrade security without triggering alerts.

Verdict

Use if: You're a red team operator or security researcher who needs to corrupt Windows Defender's integrity during post-exploitation phases while maintaining stealth, you already have admin-level access and need techniques that appear as legitimate AV behavior rather than obvious tampering, or you're studying Windows kernel attack surface and want to understand how modern minifilter TOCTOU vulnerabilities manifest in production security software. This is valuable intelligence for understanding incomplete patch implementations and designing detection strategies for symlink-based attacks. Skip if: You need practical privilege escalation or initial access tooling (the admin requirement makes this useless for that purpose), you're targeting Windows 10 systems or require compatibility across diverse Windows versions, you're building commodity malware (simple AMSI bypasses or in-memory execution are far more reliable and easier to deploy), or you're not prepared to handle the forensic artifacts—Defender's telemetry and cloud-based analysis will still record anomalous patterns even if the local exploit succeeds. For most penetration testing scenarios, directly disabling Defender through policy manipulation or using established EDR unhooking techniques will be more operationally sound than racing kernel callbacks.