ShieldCrash: Microsoft Defender 0-Day PoC Reportedly Bypasses CVE-2026-69414 Patch to Read Files as SYSTEM
Researcher Nightmare Eclipse (MSNightmare) published ShieldCrash, a Microsoft Defender zero-day PoC that reportedly bypasses the September 2026 fix for ShieldBreak (CVE-2026-69414) and enables arbitrary file reads with SYSTEM privileges on fully patched…
Zero-day researcher Nightmare Eclipse (also published as MSNightmare; The Register treats the two handles as the same person) released ShieldCrash on September 9, 2026, a proof-of-concept bypass of Microsoft's September 2026 fix for ShieldBreak (CVE-2026-69414), a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine patched in engine version 1.1.26080.3 (SecurityWeek dates the fixes to September 3). The ShieldBreak fix itself had bypassed patches for the RoguePlanet race condition (CVE-2026-50656), making ShieldCrash the third bypass in the series and suggesting Microsoft's patching of the underlying attack path is incomplete. ShieldCrash reportedly allows arbitrary file reads with SYSTEM privileges on Windows 10, Windows 11, and Windows Server systems that have applied the September 2026 patches, though it does not enable arbitrary writes, code execution, or a full SYSTEM shell. SYSTEM-level file disclosure could expose credentials, application secrets, private keys, configuration files, other users' data, and registry hives; SecurityWeek notes the PoC can dump the SAM database, supporting post-compromise reconnaissance. The PoC repository contains C++ project files, a Warden.dll library, and an EICAR test archive, suggesting interaction with Defender's malware-detection and file-handling workflow. The new flaw has no CVE assignment; Microsoft has been contacted but has not confirmed the bypass or provided a patch timeline, and no active exploitation is confirmed. One report (GBHackers) attributes to CrowdStrike that the claims remain under review. This is the researcher's 11th published Microsoft zero-day; recent releases also targeted CrowdStrike Falcon (FalconFlank), Kaspersky endpoint antivirus (HardBreacher, patched), and Gen Digital's Avast (PrettyPrague), several of which Kevin Beaumont confirmed work as described. Advised mitigations include keeping Defender engine updates enabled, enabling tamper protection, restricting admin access, monitoring Defender-related process behavior, and watching for unsigned DLLs touching Defender paths.
- ShieldCrash is an unpatched Microsoft Defender zero-day PoC enabling arbitrary file reads with SYSTEM privileges; no CVE has been assigned to the new flaw.
- Researcher: Nightmare Eclipse (Reports 1-2 use the handle MSNightmare; The Register identifies them as the same person). ShieldCrash is their 11th published Microsoft zero-day.
- Bypass target: ShieldBreak, CVE-2026-69414, a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine, patched in engine version 1.1.26080.3; SecurityWeek dates the September fixes to September 3, 2026.
- Attack chain: the CVE-2026-69414 fix had itself bypassed patches for RoguePlanet (CVE-2026-50656), a race condition; ShieldCrash is the third bypass in the series.
- Affected systems per The Register: Windows 10, Windows 11, and Windows Server with September 2026 patches applied; SOCRadar's text does not detail affected versions or exploitation status.
- Impact: reading credentials, application secrets, private keys, configuration files, other users' data, and registry hives as SYSTEM; SecurityWeek says the PoC can dump the SAM database. No arbitrary writes, code execution, or full SYSTEM…
- PoC repository contains C++ project files, a Warden.dll library, and an EICAR test archive, suggesting interaction with Defender's malware-detection and file-handling workflow.
- Status: Microsoft has not confirmed the bypass or given a patch timeline; no active exploitation is confirmed. GBHackers attributes to CrowdStrike that the claims remain under review.
Coverage timelineoldest first · each row is one article
- · 7d agoWindows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM
GBHackers· 60
Unpatched Windows Defender zero-day 'ShieldCrash' PoC lets local attackers read arbitrary files as SYSTEM, apparently bypassing the CVE-2026-69414 patch.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". NVD description · AI analysis pending | 7.0 | 11% | PoC |
| — | |
| CVE-2026-69414 | Local Elevation of Privilege in Microsoft Defender Malware Protection Engine CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists. Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass. | 7.8 | <1% |
| masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows) |