New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
Researcher Nightmare Eclipse released ShieldCrash, a Microsoft Defender zero-day PoC bypassing ShieldBreak patches to gain System privileges on Windows.
The researcher known as Nightmare Eclipse released a PoC zero-day exploit dubbed ShieldCrash against Microsoft Defender on fully patched Windows systems. The exploit grants arbitrary file read with System privileges and can be used to drop the SAM database. It bypasses Microsoft's September 3 fixes for ShieldBreak (CVE-2026-69414), which itself bypassed patches for the RoguePlanet race condition (CVE-2026-50656). Microsoft has been contacted for comment and has not yet responded.
- PoC demonstrates arbitrary file read with System privileges and can dump the SAM database
- ShieldCrash bypasses September fixes for ShieldBreak (CVE-2026-69414), which bypassed RoguePlanet (CVE-2026-50656) patches
- Third bypass in the series suggests Microsoft's patching of the underlying attack path is incomplete
- Experts advise enabling Defender tamper protection, restricting admin access, and monitoring Defender-related process behavior
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". NVD description · AI analysis pending | 7.0 | 11% | PoC |
| — | |
| CVE-2026-69414 | Local Elevation of Privilege in Microsoft Defender Malware Protection Engine CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists. Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass. | 7.8 | <1% |
| masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows) |
Full article367 words · extracted from securityweek.com · click to collapse
The security researcher known as Nightmare Eclipse has released another Microsoft Defender zero-day exploit, right after Microsoft’s record-breaking September 2026 patches.
Dubbed ‘ShieldCrash’, the exploit targets fully patched Windows systems for privilege escalation.
The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare.
However, the underlying vulnerability can be exploited to gain full System privileges, allowing attackers to drop the SAM database, the researcher says.
Nightmare Eclipse also notes that the fresh zero-day is a bypass for ShieldBreak, the Microsoft Defender privilege escalation exploit dropped on the August 2026 Patch Tuesday.
ShieldBreak in turn was released as a bypass for Microsoft’s patches against RoguePlanet, a race condition bug dropped as a zero-day on June 2026 Patch Tuesday.
Advertisement. Scroll to continue reading.
Microsoft patched RoguePlanet (CVE-2026-50656) on July 19. It acknowledged ShieldBreak on August 14 and rolled out fixes for it on September 3. The bug is tracked as CVE-2026-69414.
Nightmare Eclipse says that Microsoft’s patches for ShieldBreak are incomplete, and that the security defect can still be exploited, releasing ShieldCrash as proof.
SecurityWeek has emailed Microsoft for a statement on the fresh zero-day exploit and will update this article if the company responds.
According to SOCRadar CISO Ensar Seker, ShieldCrash raises concerns mainly because it exposes a weakness in Microsoft’s patching of the underlying vulnerability’s attack paths.
“When researchers can bypass successive fixes for RoguePlanet and ShieldBreak, it suggests the underlying security boundary or attack surface may require a more comprehensive redesign rather than another narrowly targeted patch,” Seker said.
He advises security teams to monitor Microsoft’s guidance and Defender intelligence updates, enable tamper protections, restrict admin access and local execution paths, and look for any suspicious process behavior associated with Defender-related mechanisms.
“Microsoft should also assess the complete vulnerability class and related code paths, not only the specific condition demonstrated by this latest proof of concept,” Seker added.
Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Related: Android’s September 2026 Updates Patch 180 Vulnerabilities
Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/new-shieldcrash-zero-day-exploit-targets-microsoft-defender/