ZeroHour
Story · 1 source · 1 articlefirst updated ()

ShieldCrash bypass of Microsoft Defender CVE-2026-69414 caps zero-day spree hitting CrowdStrike, Nvidia, Avast and Kaspersky

What's new: SOCRadar (2026-09-10) added coverage of ShieldCrash, characterizing CVE-2026-69414 (ShieldBreak) as a high-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine and reporting that the new PoC demonstrates the released fix can be bypassed; the report did not detail affected versions or real-world exploitation. No new patches, CVE assignments, vendor fixes or…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Researcher Nightmare Eclipse (aka Chaotic Eclipse, MSNightmare) published ShieldCrash on 2026-09-09, a PoC that bypasses Microsoft Defender's fix for CVE-2026-69414 (ShieldBreak) to read arbitrary files as SYSTEM on fully patched Windows — counted by The…

Security researcher Nightmare Eclipse — also credited as Chaotic Eclipse (Security Affairs) and MSNightmare (GBHackers) — published a rapid series of zero-day proof-of-concept exploits in early September 2026. FalconFlank (disclosed 2026-09-03) abuses CrowdStrike Falcon Sensor's Microsoft Office malicious macro removal feature, which runs with high privileges, for local privilege escalation on fully patched Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection; CrowdStrike is investigating and advises disabling the Microsoft Office File Suspicious Macro Removal Windows policy, with customers kept protected by Cloud Anti-malware for Microsoft Office Files; no CVE has been assigned, and Security Affairs framed the case as an example of EDR elevated privileges becoming a local privilege escalation attack surface. PrettyPrague targets the Avast sandbox, dumping the SAM database for a SYSTEM shell and possibly extending to other GenDigital products including AVG and Norton; The Register reported on Sep 3 that Gen Digital was developing a patch, and by Sep 7 SecurityWeek reported GenDigital said it had fixed the issue. HardBreacher, a Kaspersky Endpoint Security elevation-of-privilege zero-day, was patched August 31, 2026. GreenSection exploits an out-of-bounds write tied to NVIDIA's Windows user-mode components, which share a global memory section (\BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba}) with full read/write access to all users; the PoC crashes Vulkan/OpenGL applications and may allow cross-user access or compromise of dwm.exe, though the researcher did not fully assess impact; NVIDIA said on Sep 7 it is actively investigating, with no patch or CVE mentioned. The newest release, ShieldCrash (2026-09-09), performs arbitrary file reads as SYSTEM on fully patched Windows — described by Security Affairs as all supported Windows versions and by The Register specifically as Windows 10, 11 and Server — and per SecurityWeek can be used to drop the SAM database, though The Register notes it does not yet enable arbitrary writes or a full SYSTEM shell. The researcher says Microsoft's patch fixed several exploit paths but missed a specific condition; ShieldCrash bypasses the September 2026 fixes (dated September 3 by SecurityWeek) for ShieldBreak (CVE-2026-69414) in Malware Protection Engine 1.1.26080.3, which themselves had bypassed the RoguePlanet race-condition fix (CVE-2026-50656). Microsoft has been contacted but has not…

  • FalconFlank (disclosed 2026-09-03): PoC privilege escalation abusing CrowdStrike Falcon Sensor's Microsoft Office malicious macro removal feature, which runs with high privileges; verified on fully patched Windows 11 25H2 and Windows…
  • CrowdStrike's FalconFlank mitigation: disable the Microsoft Office File Suspicious Macro Removal Windows policy while it investigates; customers remain protected by Cloud Anti-malware for Microsoft Office Files.
  • ShieldCrash (2026-09-09): PoC bypass of the fix for CVE-2026-69414 (ShieldBreak), an elevation-of-privilege flaw in the Microsoft Malware Protection Engine that SOCRadar describes as high severity; works on systems with the September 2026…
  • ShieldCrash enables arbitrary file reads as SYSTEM; SecurityWeek says it can dump the SAM database, while The Register notes it does not yet enable arbitrary writes or a full SYSTEM shell; affected scope is described by Security Affairs as…
  • Bypass chain: ShieldBreak (CVE-2026-69414) fixes of September 3, 2026 (per SecurityWeek) had themselves bypassed the RoguePlanet race-condition fix (CVE-2026-50656); ShieldCrash is the third bypass in the series and The Register counts it…
  • ShieldCrash status: no new CVE assigned, Microsoft contacted with no response on patch timeline, no active exploitation confirmed, and no specific mitigation available at disclosure; experts advise keeping engine updates enabled, enabling…
  • GreenSection: out-of-bounds write tied to NVIDIA Windows user-mode components sharing a global memory section \BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba} with full read/write access for all users; PoC crashes Vulkan or OpenGL…
  • PrettyPrague: Avast sandbox PoC that dumps the SAM database for a SYSTEM shell; possibly affects other GenDigital products including AVG and Norton; The Register (Sep 3) reported a patch in development and SecurityWeek (Sep 7) reported…

Coverage timeline

  1. · 13d ago
    The Register · Security· 55
    Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

    Researcher Nightmare Eclipse released a PoC for FalconFlank, a privilege escalation zero-day in CrowdStrike Falcon's Office macro remediation feature.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50656
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

NVD description · AI analysis pending
7.011% PoC
  • microsoft malware protection engine
CVE-2026-69414
Local Elevation of Privilege in Microsoft Defender Malware Protection Engine

CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists.

Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass.

7.8<1%
  • Microsoft Malware Protection Engine (used in Microsoft Defender)
masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows)