New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
Researcher Nightmare Eclipse released 'ShieldCrash', a zero-day exploit for Microsoft Defender that grants attackers SYSTEM-level access.
An anonymous researcher known as Nightmare Eclipse published a zero-day exploit for Microsoft Defender, dubbed 'ShieldCrash', that yields SYSTEM-level access. The release came immediately after Microsoft rolled out its September 2026 Patch Tuesday security updates. No CVE identifier has been assigned publicly and no in-the-wild exploitation has been reported yet. Microsoft Defender ships by default on Windows, so potential exposure is broad until Microsoft patches the flaw.
- Zero-day exploit named ShieldCrash targets Microsoft Defender and grants SYSTEM privileges.
- Released by anonymous researcher Nightmare Eclipse right after September 2026 Patch Tuesday.
- No CVE assigned and no confirmed in-the-wild exploitation so far.
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at bleepingcomputer.com.