ZeroHour
Story · 7 sources · 8 articlesfirst updated ()

ShieldCrash PoC Bypasses Microsoft's ShieldBreak Patch (CVE-2026-69414), Enabling Arbitrary File Reads as SYSTEM on Patched Windows

What's new: First merged summary of this story. On September 9, 2026, the researcher released the ShieldCrash PoC demonstrating a bypass of Microsoft's September 3, 2026 patch for CVE-2026-69414 in Malware Protection Engine 1.1.26080.3; the new flaw has no CVE assignment, Microsoft has not confirmed the bypass or committed to a patch timeline, and no active exploitation has been reported.
Merged summary · glm-5.3 · rewritten as coverage arrives

A zero-day researcher (variously named Chaotic Eclipse, Nightmare Eclipse, and MSNightmare across sources) released ShieldCrash, a proof-of-concept showing Microsoft Defender still permits arbitrary file reads with SYSTEM privileges on fully patched Windows,…

On September 9, 2026, a prolific zero-day researcher released a proof-of-concept dubbed ShieldCrash against Microsoft Defender. Sources use different names for the same researcher — The Hacker News and Security Affairs call them 'Chaotic Eclipse', GBHackers and Cyber Security News call them 'MSNightmare', and The Register and SecurityWeek use 'Nightacle Eclipse'/'Nightmare Eclipse'; The Register identifies Nightmare Eclipse and MSNightmare as the same person, and Security Affairs notes Chaotic Eclipse is also known as Nightmare Eclipse. ShieldCrash is assessed as a patch bypass for ShieldBreak (CVE-2026-69414, CVSS 7.8), a high-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine that Microsoft fixed on September 3, 2026 in engine version 1.1.26080.3, which updates automatically. Per The Register and SecurityWeek, ShieldBreak itself had bypassed the fix for RoguePlanet (CVE-2026-50656), making ShieldCrash the third bypass in a series that suggests Microsoft's patching of the underlying attack path is incomplete. The PoC demonstrates arbitrary file reads with SYSTEM privileges on Windows 10, Windows 11, and Windows Server systems running the September 2026 updates and engine 1.1.26080.3; the researcher claims Microsoft's patch closed several exploit paths but missed a specific condition. The Register notes the exploit does not enable arbitrary writes or a full SYSTEM shell, though SecurityWeek reports it can be used to dump the SAM database, and SYSTEM-level reads could expose credentials, private keys, configuration files, registry hives, and other users' data. The PoC repository contains C++ project files, a Warden.dll library, and an EICAR test archive, suggesting interaction with Defender's malware-detection and file-handling workflow. The new flaw has no CVE assignment yet, Microsoft has not confirmed the bypass or provided a patch timeline, and no active exploitation is confirmed; Kevin Beaumont independently confirmed that several of the researcher's recent exploits work as described. ShieldCrash is the researcher's 11th Microsoft zero-day, following recent PoCs against CrowdStrike Falcon (FalconFlank), Kaspersky Endpoint Security (HardBreacher, since patched), Avast (PrettyPrague, possibly extending to AVG and Norton), and NVIDIA. Advised defenses include keeping engine updates enabled, enabling Defender tamper protection, restricting admin access, watching for unsigned DLLs touching Defender paths, and…

  • ShieldCrash PoC demonstrates arbitrary file reads with SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems with the September 2026 updates applied.
  • It bypasses Microsoft's September 3, 2026 fix for ShieldBreak (CVE-2026-69414, CVSS 7.8), a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine, patched in engine version 1.1.26080.3 (which updates…
  • Per The Register and SecurityWeek, ShieldBreak (CVE-2026-69414) itself bypassed the fix for RoguePlanet (CVE-2026-50656), making ShieldCrash the third bypass in a chain, suggesting Microsoft's patching of the underlying attack path is…
  • The Register states the exploit enables reads but not arbitrary writes or a full SYSTEM shell; SecurityWeek reports it can dump the SAM database; exposed data could include credentials, private keys, configuration files, registry hives,…
  • The researcher claims the September patch fixed several exploit paths but missed a specific condition that still enables the attack.
  • The PoC repository contains C++ project files, a Warden.dll library, and an EICAR test archive, indicating interaction with Defender's malware-detection and file-handling workflow.
  • No new CVE has been assigned for ShieldCrash; Microsoft has not confirmed the bypass, awaits independent reproduction, and has given no patch timeline; no active exploitation is confirmed.
  • The researcher is identified by different aliases across sources — Chaotic Eclipse (The Hacker News, Security Affairs), MSNightmare (GBHackers, Cyber Security News), and Nightmare Eclipse (The Register, SecurityWeek) — with The Register…

Coverage timeline

  1. · 6d ago
    The Hacker News· 45
    Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

    Researcher Chaotic Eclipse released a PoC showing CVE-2026-69414's patch is bypassable, allowing arbitrary file reads as SYSTEM on current Windows.

  2. · 6d ago
    Security Affairs· 72
    Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

    Researcher Chaotic Eclipse released ShieldCrash, a PoC showing Microsoft Defender's CVE-2026-69414 patch is incomplete, enabling arbitrary file reads as SYSTEM.

  3. · 6d ago
    GBHackers· 60
    Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM

    Unpatched Windows Defender zero-day 'ShieldCrash' PoC lets local attackers read arbitrary files as SYSTEM, apparently bypassing the CVE-2026-69414 patch.

  4. · 6d ago
    Cyber Security News· 45
    New Windows Defender ShieldCrash 0-Day Bypasses Microsoft Patch to Read Files as SYSTEM

    Researcher's ShieldCrash PoC claims Microsoft Defender still allows arbitrary file reads as SYSTEM on patched Windows, bypassing the CVE-2026-69414 fix.

  5. · 6d ago
    Security Affairs· 72
    Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

    Researcher Chaotic Eclipse released FalconFlank, a PoC zero-day privilege escalation exploit against CrowdStrike Falcon's Microsoft Office macro removal feature.

  6. · 6d ago
    The Register · Security· 55
    Serial Microsoft 0-day hunter drops yet another Defender exploit

    Researcher Nightmare Eclipse released ShieldCrash, a Microsoft Defender zero-day PoC that bypasses September patches and reads files as SYSTEM.

  7. · 5d ago
    SecurityWeek· 65
    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    Researcher Nightmare Eclipse released ShieldCrash, a Microsoft Defender zero-day PoC bypassing ShieldBreak patches to gain System privileges on Windows.

  8. · 5d ago
    SOCRadar· 62
    ShieldCrash PoC: Microsoft Defender Fix Bypass

    A ShieldCrash proof-of-concept bypasses Microsoft's patch for CVE-2026-69414, a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50656
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

NVD description · AI analysis pending
7.011% PoC
  • microsoft malware protection engine
CVE-2026-69414
Local Elevation of Privilege in Microsoft Defender Malware Protection Engine

CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists.

Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass.

7.8<1%
  • Microsoft Malware Protection Engine (used in Microsoft Defender)
masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows)