Search: “Microsoft Malware Protection Engine”
141 stories
Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day
Researcher Chaotic Eclipse released ShieldCrash, a PoC showing Microsoft Defender's CVE-2026-69414 patch is incomplete, enabling arbitrary file reads as SYSTEM.
Security researcher Chaotic Eclipse published ShieldCrash, a proof-of-concept exploit for the Microsoft Malware Protection Engine privilege escalation vulnerability CVE-2026-69414 (ShieldBreak). The PoC performs arbitrary file reads with SYSTEM privileges on all supported Windows versions, including systems running the September 2026 security updates and Malware Protection Engine version 1.1.26080.3. The researcher claims Microsoft's patch fixed several exploit paths but missed a specific condition that still enables the attack. His recent releases also include zero-day PoCs targeting Nvidia, Kaspersky, Avast, and CrowdStrike Falcon.
ShieldCrash PoC: Microsoft Defender Fix Bypass
A ShieldCrash proof-of-concept bypasses Microsoft's patch for CVE-2026-69414, a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine.
Microsoft previously fixed CVE-2026-69414 (ShieldBreak), a high-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender. SOCRadar now reports a new proof-of-concept dubbed ShieldCrash demonstrating that the published fix can be bypassed. The available source text does not detail affected versions or whether the bypass has been used in real attacks.
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
Researcher Chaotic Eclipse released ShieldBreak PoC, a claimed patch bypass for Microsoft Defender flaw CVE-2026-50656, now tracked as CVE-2026-69414.
Researcher Chaotic Eclipse released a PoC for ShieldBreak, a claimed full patch bypass of Microsoft Defender flaw CVE-2026-50656 (RoguePlanet), which can yield SYSTEM privileges. Independent researchers Kevin Beaumont and Will Dormann validated the exploit on Windows 11 25H2 and Windows Server 2025, noting it requires Defender to be enabled. Microsoft assigned CVE-2026-69414 (CVSS 7.8) with an 'Exploitation More Likely' assessment and is investigating, but has not yet released a patch. The article also notes CISA's KEV addition of the actively exploited Windows AFD.sys flaw CVE-2026-68820.
Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM
Unpatched Windows Defender zero-day 'ShieldCrash' PoC lets local attackers read arbitrary files as SYSTEM, apparently bypassing the CVE-2026-69414 patch.
Researcher MSNightmare published a skeleton proof-of-concept for 'ShieldCrash', an unpatched Microsoft Defender flaw enabling arbitrary file reads with SYSTEM privileges that reportedly persists on supported Windows versions after September 2026 updates. It appears to bypass the recent fix for the Malware Protection Engine elevation-of-privilege flaw CVE-2026-69414 (ShieldBreak), patched in engine version 1.1.26080.3. SYSTEM-level file disclosure could expose credentials, application secrets and registry hives and support post-compromise reconnaissance. No active exploitation is confirmed and Microsoft had issued no specific patch or mitigation at disclosure time.
14th September – Threat Intelligence Report
Check Point weekly digest: Microsoft's record 974-vuln Patch Tuesday ships two actively exploited Windows zero-days; IDScan.net, Mathspace, Revolut suffer breaches.
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited privilege-escalation zero-days, CVE-2026-85880 and CVE-2026-81963, plus 20 flaws allowing unauthenticated remote code execution. Disclosed breaches include IDScan.net (identity documents), Mathspace (over 1 million people via Metabase CVE-2026-72898), Revolut, and Florida DMV (ShinyHunters). GitLab fixed critical CVSS 10.0 path traversal CVE-2026-85706, and MikroTik fixed chainable RouterOS flaws CVE-2026-67276 and CVE-2026-86060. The report also covers the PuzzleMask LLM jailbreak technique, GoldFactory's Gigabud Android fraud, and the BlueMoon Chromium exploit chain (CVE-2026-85046).
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
Researcher Nightmare Eclipse released working zero-day PoCs for Avast, CrowdStrike Falcon, and Nvidia, prompting a Gen patch, CrowdStrike mitigation, and Nvidia investigation.
Security researcher Nightmare Eclipse released three zero-day exploits within a short window: PrettyPrague targeting the Avast sandbox for full system privileges (possibly affecting other GenDigital products including AVG and Norton), FalconFlank exploiting CrowdStrike Falcon Sensor's Office malicious macros remediation feature for privilege escalation, and GreenSection targeting an out-of-bounds memory write in a shared global memory section used by Nvidia user-mode components. GenDigital said it has fixed the Avast issue; CrowdStrike advised disabling the Microsoft Office File Suspicious Macro Removal policy setting; Nvidia said it is actively investigating the PoC. Kevin Beaumont reported that the Avast, CrowdStrike, and Kaspersky exploits work. The researcher previously released the HardBreacher privilege escalation zero-day in Kaspersky endpoint security, patched August 31.