Serial Microsoft 0-day hunter drops yet another Defender exploit
Researcher Nightmare Eclipse released ShieldCrash, a Microsoft Defender zero-day PoC that bypasses September patches and reads files as SYSTEM.
Zero-day researcher Nightmare Eclipse (MSNightmare) published ShieldCrash, their 11th Microsoft zero-day, a proof-of-concept bypass of the ShieldBreak patch (CVE-2026-69414), which itself had bypassed the fix for RoguePlanet (CVE-2026-50656). ShieldCrash works on Windows 10, Windows 11, and Windows Server systems that have applied the September 2026 patches and allows arbitrary file reads as SYSTEM, though not arbitrary writes or a full SYSTEM shell. Microsoft has not said when it plans to patch the issue. The researcher recently also released zero-days affecting CrowdStrike Falcon (FalconFlank), Kaspersky endpoint antivirus (HardBreacher, patched), and Gen Digital's Avast (PrettyPrague).
- ShieldCrash is a bypass of the ShieldBreak patch (CVE-2026-69414), which itself bypassed the RoguePlanet fix (CVE-2026-50656).
- Enables arbitrary file reads as SYSTEM on fully patched Windows 10, 11 and Server; no writes or full SYSTEM shell yet.
- It is Nightmare Eclipse's 11th Microsoft zero-day; recent releases also hit CrowdStrike Falcon, Kaspersky, and Avast.
- Kevin Beaumont confirmed several of the researcher's recent exploits, including FalconFlank and HardBreacher, work as described.
- Microsoft has not yet responded on a patch timeline for ShieldCrash.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". NVD description · AI analysis pending | 7.0 | 11% | PoC |
| — | |
| CVE-2026-69414 | Local Elevation of Privilege in Microsoft Defender Malware Protection Engine CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists. Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass. | 7.8 | <1% |
| masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows) |
Full article363 words · extracted from theregister.com · click to collapse
security
A bypass of a bypass of a bypass
Zero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed ShieldCrash, which they claim will allow attackers to bypass the earlier ShieldBreak patch and read files as SYSTEM.
“I might rework this later into a full SYSTEM PoC but for now I'm dropping this skeleton PoC because I'm feeling a bit lazy,” the prolific Microsoft bug hunter and thorn in Redmond's side said in their latest zero-day exploit's README.
As is usual with Nightmare’s zero-day cadence, they published ShieldCrash shortly after Microsoft released its latest Patch Tuesday security updates. According to Nightmare, this exploit works on Windows systems that have already applied the September patches.
REG AD
ShieldCrash purports to be a bypass of an earlier Defender privilege escalation zero-day, ShieldBreak (CVE-2026-69414), that allowed attackers to bypass another patch for another Nightmare Eclipse zero-day RoguePlanet (CVE-2026-50656).
REG AD
Redmond patched ShieldBreak last week, and RoguePlanet in July. Both allowed attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
The latest bypass, ShieldCrash, allows arbitrary file reads as SYSTEM - but not arbitrary writes or a full SYSTEM shell, according to the researcher.
Microsoft did not immediately respond to The Register’s questions, including when it planned to patch ShieldCrash. We will update this story when we hear back.
While the serial bug hunter typically finds and publishes Microsoft exploits - ShieldCrash is Nightmare’s 11th Microsoft zero-day, and they have made clear that with Redmond, their vendetta is personal - they recently branched out into other security vendors’ software.
Last week, they released a zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform. This one still has a Windows twist: the privilege escalation bug abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon.
Security sleuth Kevin Beaumont confirmed the FalconFlank exploit works, along with several others Nightmare released over the past couple of weeks. These include HardBreacher, a now-patched elevation of privileges bug in Kaspersky’s endpoint antivirus product, and PrettyPrague, an elevation of privileges vuln in Gen Digital’s Avast antivirus software. ®
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335