ZeroHour
Story · 1 source · 1 articlefirst updated ()1

ShieldCrash: Nightmare Eclipse publishes third Microsoft Defender bypass, reading files as SYSTEM on fully patched Windows

What's new: No new developments since the previous story summary (2026-09-16): the three source reports (The Register 2026-09-09, SecurityWeek 2026-09-10, SOCRadar 2026-09-10) predate it, and Microsoft still had not responded as of the latest report (2026-09-10). This merge consolidates the ShieldCrash coverage into a single story and, unlike the previous summary, excludes the separate Microsoft Threat…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Zero-day researcher Nightmare Eclipse released ShieldCrash, an 11th Microsoft zero-day PoC that bypasses the September 2026 ShieldBreak patch (CVE-2026-69414) and enables arbitrary file reads as SYSTEM on fully patched Windows 10, 11 and Server; Microsoft has…

Zero-day researcher Nightmare Eclipse (MSNightmare) has published ShieldCrash, described by The Register as their 11th Microsoft zero-day: a proof-of-concept bypass of Microsoft's September 2026 patches (SecurityWeek specifies the September 3 fixes) for ShieldBreak, tracked as CVE-2026-69414, which SOCRadar describes as a high-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender. ShieldBreak itself had bypassed the fix for the RoguePlanet race condition (CVE-2026-50656), making ShieldCrash the third bypass in the series and suggesting Microsoft's patching of the underlying attack path is incomplete. On Windows 10, Windows 11, and Windows Server systems running the September patches, the PoC enables arbitrary file reads as SYSTEM and can be used to dump the SAM database; no arbitrary writes or a full SYSTEM shell are demonstrated. Microsoft was contacted for comment and had not responded as of the latest report (2026-09-10), and no patch timeline has been given. SecurityWeek reports experts advise enabling Defender tamper protection, restricting admin access, and monitoring Defender-related process behavior, while SOCRadar notes exploitation status in the wild and affected versions are not detailed in the available text. The researcher's recent releases also include FalconFlank (CrowdStrike Falcon), HardBreacher (Kaspersky endpoint antivirus, patched), and PrettyPrague (Gen Digital's Avast); Kevin Beaumont confirmed FalconFlank and HardBreacher work as described.

  • ShieldCrash is a proof-of-concept zero-day against Microsoft Defender published by researcher Nightmare Eclipse (MSNightmare); The Register counts it as their 11th Microsoft zero-day.
  • ShieldCrash bypasses Microsoft's September 2026 fixes (SecurityWeek specifies September 3) for ShieldBreak, CVE-2026-69414, a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine (per SOCRadar).
  • ShieldBreak itself had bypassed patches for the RoguePlanet race condition, CVE-2026-50656; ShieldCrash is therefore the third bypass in the series, suggesting Microsoft's patching of the underlying attack path is incomplete.
  • The PoC works on fully patched Windows 10, Windows 11, and Windows Server systems and enables arbitrary file reads as SYSTEM; SecurityWeek adds it can be used to dump the SAM database.
  • No arbitrary file writes or a full SYSTEM shell are demonstrated.
  • Microsoft was contacted for comment and had not responded as of 2026-09-10, and no patch timeline has been announced.
  • SOCRadar notes that real-world exploitation status and affected versions are not detailed in the available text.
  • Experts cited by SecurityWeek advise enabling Defender tamper protection, restricting admin access, and monitoring Defender-related process behavior.

Coverage timeline

  1. · 7d ago
    The Register · Security· 55
    Serial Microsoft 0-day hunter drops yet another Defender exploit

    Researcher Nightmare Eclipse released ShieldCrash, a Microsoft Defender zero-day PoC that bypasses September patches and reads files as SYSTEM.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50656
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

NVD description · AI analysis pending
7.011% PoC
  • microsoft malware protection engine
CVE-2026-69414
Local Elevation of Privilege in Microsoft Defender Malware Protection Engine

CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists.

Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass.

7.8<1%
  • Microsoft Malware Protection Engine (used in Microsoft Defender)
masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows)