ShieldCrash bypass of Microsoft Defender CVE-2026-69414 caps zero-day spree hitting CrowdStrike, Nvidia, Avast and Kaspersky
Researcher Nightmare Eclipse (aka Chaotic Eclipse, MSNightmare) published ShieldCrash on 2026-09-09, a PoC that bypasses Microsoft Defender's fix for CVE-2026-69414 (ShieldBreak) to read arbitrary files as SYSTEM on fully patched Windows — counted by The…
Security researcher Nightmare Eclipse — also credited as Chaotic Eclipse (Security Affairs) and MSNightmare (GBHackers) — published a rapid series of zero-day proof-of-concept exploits in early September 2026. FalconFlank (disclosed 2026-09-03) abuses CrowdStrike Falcon Sensor's Microsoft Office malicious macro removal feature, which runs with high privileges, for local privilege escalation on fully patched Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection; CrowdStrike is investigating and advises disabling the Microsoft Office File Suspicious Macro Removal Windows policy, with customers kept protected by Cloud Anti-malware for Microsoft Office Files; no CVE has been assigned, and Security Affairs framed the case as an example of EDR elevated privileges becoming a local privilege escalation attack surface. PrettyPrague targets the Avast sandbox, dumping the SAM database for a SYSTEM shell and possibly extending to other GenDigital products including AVG and Norton; The Register reported on Sep 3 that Gen Digital was developing a patch, and by Sep 7 SecurityWeek reported GenDigital said it had fixed the issue. HardBreacher, a Kaspersky Endpoint Security elevation-of-privilege zero-day, was patched August 31, 2026. GreenSection exploits an out-of-bounds write tied to NVIDIA's Windows user-mode components, which share a global memory section (\BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba}) with full read/write access to all users; the PoC crashes Vulkan/OpenGL applications and may allow cross-user access or compromise of dwm.exe, though the researcher did not fully assess impact; NVIDIA said on Sep 7 it is actively investigating, with no patch or CVE mentioned. The newest release, ShieldCrash (2026-09-09), performs arbitrary file reads as SYSTEM on fully patched Windows — described by Security Affairs as all supported Windows versions and by The Register specifically as Windows 10, 11 and Server — and per SecurityWeek can be used to drop the SAM database, though The Register notes it does not yet enable arbitrary writes or a full SYSTEM shell. The researcher says Microsoft's patch fixed several exploit paths but missed a specific condition; ShieldCrash bypasses the September 2026 fixes (dated September 3 by SecurityWeek) for ShieldBreak (CVE-2026-69414) in Malware Protection Engine 1.1.26080.3, which themselves had bypassed the RoguePlanet race-condition fix (CVE-2026-50656). Microsoft has been contacted but has not…
- FalconFlank (disclosed 2026-09-03): PoC privilege escalation abusing CrowdStrike Falcon Sensor's Microsoft Office malicious macro removal feature, which runs with high privileges; verified on fully patched Windows 11 25H2 and Windows…
- CrowdStrike's FalconFlank mitigation: disable the Microsoft Office File Suspicious Macro Removal Windows policy while it investigates; customers remain protected by Cloud Anti-malware for Microsoft Office Files.
- ShieldCrash (2026-09-09): PoC bypass of the fix for CVE-2026-69414 (ShieldBreak), an elevation-of-privilege flaw in the Microsoft Malware Protection Engine that SOCRadar describes as high severity; works on systems with the September 2026…
- ShieldCrash enables arbitrary file reads as SYSTEM; SecurityWeek says it can dump the SAM database, while The Register notes it does not yet enable arbitrary writes or a full SYSTEM shell; affected scope is described by Security Affairs as…
- Bypass chain: ShieldBreak (CVE-2026-69414) fixes of September 3, 2026 (per SecurityWeek) had themselves bypassed the RoguePlanet race-condition fix (CVE-2026-50656); ShieldCrash is the third bypass in the series and The Register counts it…
- ShieldCrash status: no new CVE assigned, Microsoft contacted with no response on patch timeline, no active exploitation confirmed, and no specific mitigation available at disclosure; experts advise keeping engine updates enabled, enabling…
- GreenSection: out-of-bounds write tied to NVIDIA Windows user-mode components sharing a global memory section \BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba} with full read/write access for all users; PoC crashes Vulkan or OpenGL…
- PrettyPrague: Avast sandbox PoC that dumps the SAM database for a SYSTEM shell; possibly affects other GenDigital products including AVG and Norton; The Register (Sep 3) reported a patch in development and SecurityWeek (Sep 7) reported…
Coverage timelineoldest first · each row is one article
- · 13d agoProlific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
The Register · Security· 55
Researcher Nightmare Eclipse released a PoC for FalconFlank, a privilege escalation zero-day in CrowdStrike Falcon's Office macro remediation feature.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". NVD description · AI analysis pending | 7.0 | 11% | PoC |
| — | |
| CVE-2026-69414 | Local Elevation of Privilege in Microsoft Defender Malware Protection Engine CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists. Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass. | 7.8 | <1% |
| masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows) |