ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Nightmare Eclipse Zero-Day Wave Hits CrowdStrike Falcon, Avast, Nvidia, and Microsoft Defender

What's new: 2026-09-07: FalconFlank (CrowdStrike), PrettyPrague (Avast), and GreenSection (Nvidia) disclosed; CrowdStrike issued the Suspicious Macro Removal policy mitigation, GenDigital said it patched the Avast flaw, and Nvidia said it is actively investigating; Kevin Beaumont confirmed the Avast, CrowdStrike, and Kaspersky exploits work.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Researcher Nightmare Eclipse (published as Chaotic Eclipse / MSNightmare across sources) disclosed a rapid series of zero-day PoCs on 2026-09-07 through 2026-09-09: FalconFlank (CrowdStrike Falcon Sensor LPE via the Office macro-removal feature; mitigation…

In early September 2026, the researcher Nightmare Eclipse — whose releases appear under the names Chaotic Eclipse and MSNightmare in the reports — published a cluster of zero-day proof-of-concept exploits against Windows endpoint-security products. Kevin Beaumont independently confirmed that the Avast, CrowdStrike, and Kaspersky exploits work as described. CrowdStrike: FalconFlank is a local privilege escalation in Falcon Sensor that abuses the Microsoft Office malicious macro removal remediation feature, which runs with high privileges. It was verified working on fully updated Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection. CrowdStrike urged customers to disable the Microsoft Office File Suspicious Macro Removal policy while it investigates, noting customers remain protected by Cloud Anti-malware for Microsoft Office Files; no CVE has been assigned. Avast/GenDigital: PrettyPrague exploits the Avast sandbox for full system privileges and reportedly dumps the SAM database for a SYSTEM shell; it may affect other GenDigital products including AVG and Norton. GenDigital said it has fixed the issue. Nvidia: GreenSection exploits an out-of-bounds write in Nvidia's Windows user-mode components, which share a global memory section (\BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba}) with full read/write access to all users. The unstable PoC crashes applications using Vulkan or OpenGL and could potentially cross user boundaries or compromise dwm.exe, though impact was not fully assessed; no CVE or patch has been announced and Nvidia said it is actively investigating. Microsoft Defender: ShieldCrash — the researcher's 11th Microsoft zero-day per The Register — performs arbitrary file reads with SYSTEM privileges on supported Windows 10, 11, and Server systems running the September 2026 updates and Malware Protection Engine version 1.1.26080.3. It bypasses the September 3, 2026 fix for ShieldBreak (CVE-2026-69414, a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine), which itself had bypassed fixes for the RoguePlanet race condition (CVE-2026-50656) — the third bypass in the series. It does not yet grant arbitrary writes or a full SYSTEM shell, but can dump the SAM database. Sources associate CVE-2026-69414 with ShieldBreak and note that ShieldCrash itself has no separate CVE; no active exploitation is confirmed, and Microsoft had not responded on a patch timeline as of 2026-09-10. Context: the…

  • FalconFlank: local privilege escalation in CrowdStrike Falcon Sensor abusing the Microsoft Office malicious macro removal remediation feature (runs with high privileges); verified on fully updated Windows 11 25H2 and Windows Server 2025…
  • CrowdStrike mitigation: disable the Microsoft Office File Suspicious Macro Removal Windows policy; customers remain protected by Cloud Anti-malware for Microsoft Office Files while the company investigates.
  • PrettyPrague: privilege escalation via the Avast sandbox, reportedly dumping the SAM database for a SYSTEM shell; possibly affects other GenDigital products including AVG and Norton; GenDigital says it has fixed the issue.
  • GreenSection: out-of-bounds write in Nvidia Windows user-mode components that share global section \BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba} with full read/write access for all users; PoC crashes Vulkan/OpenGL applications;…
  • ShieldCrash: arbitrary file read with SYSTEM privileges on supported Windows 10/11/Server with September 2026 updates and Malware Protection Engine 1.1.26080.3; no arbitrary writes or full SYSTEM shell yet; can dump the SAM database.
  • ShieldCrash bypasses the September 3, 2026 fix for ShieldBreak (CVE-2026-69414, high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine), which itself bypassed fixes for RoguePlanet (CVE-2026-50656) — the third…
  • No separate CVE assigned to ShieldCrash itself; no confirmed in-the-wild exploitation; Microsoft had not announced a patch timeline as of 2026-09-10.
  • ShieldCrash is the researcher's 11th Microsoft zero-day (The Register).

Coverage timeline

  1. · 9d ago
    Infosecurity Magazine· 62
    Researcher Publishes CrowdStrike Privilege Escalation Zero Day

    Researcher NightmareEclipse published FalconFlank, a zero-day local privilege escalation in CrowdStrike Falcon Sensor abusing its Office malicious macro remediation feature.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50656
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

NVD description · AI analysis pending
7.011% PoC
  • microsoft malware protection engine
CVE-2026-69414
Local Elevation of Privilege in Microsoft Defender Malware Protection Engine

CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists.

Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass.

7.8<1%
  • Microsoft Malware Protection Engine (used in Microsoft Defender)
masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows)