ShieldCrash PoC Bypasses Microsoft Defender ShieldBreak Patch (CVE-2026-69414), Enables SYSTEM-Level Arbitrary File Reads on Fully Patched Windows
Researcher Nightmare Eclipse (aka Chaotic Eclipse / MSNightmare) released ShieldCrash, a PoC that bypasses Microsoft's September 3, 2026 fix for Defender flaw CVE-2026-69414 and reads arbitrary files as SYSTEM on fully patched Windows 10, 11 and Server;…
Security researcher Nightmare Eclipse — referred to across reports as Chaotic Eclipse or MSNightmare, with two reports indicating these names refer to the same person — published ShieldCrash, a proof-of-concept zero-day against Microsoft Defender and the Microsoft Malware Protection Engine. ShieldCrash enables arbitrary file reads with SYSTEM privileges on Windows 10, Windows 11 and Windows Server systems running the September 2026 security updates (described by one report as all supported Windows versions), though it does not permit arbitrary writes or a full SYSTEM shell; one report says it can dump the SAM database. It bypasses Microsoft's September 3, 2026 fix for ShieldBreak (CVE-2026-69414), a high-severity elevation-of-privilege flaw patched in Malware Protection Engine version 1.1.26080.3 — a fix that itself had bypassed patches for the RoguePlanet race condition (CVE-2026-50656) — making ShieldCrash the third bypass in the series and, per one report, the researcher's 11th Microsoft zero-day. The new flaw has no CVE. Microsoft has not confirmed the bypass, responded to requests for comment, or given a patch timeline; no active exploitation is confirmed as of 2026-09-10. SYSTEM-level reads could expose credentials, application secrets, private keys, registry hives and other users' data, but not code execution. The same researcher recently released zero-day PoCs against CrowdStrike Falcon (FalconFlank), Kaspersky Endpoint Security (HardBreacher, reported patched) and Avast (PrettyPrague), plus Nvidia per one report; Kevin Beaumont confirmed several, including FalconFlank and HardBreacher, work as described.
- ShieldCrash is a PoC zero-day that reads arbitrary files with SYSTEM privileges on fully patched Windows 10, Windows 11 and Windows Server (September 2026 updates applied); it does not enable arbitrary writes or a full SYSTEM shell.
- It bypasses the fix for ShieldBreak (CVE-2026-69414), a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine, patched in engine version 1.1.26080.3 as part of Microsoft's September 3, 2026 fixes.
- The ShieldBreak fix itself bypassed patches for the RoguePlanet race condition (CVE-2026-50656), making ShieldCrash the third bypass in the RoguePlanet -> ShieldBreak -> ShieldCrash chain and suggesting Microsoft's patching of the…
- The new flaw has no CVE assignment; Microsoft has not confirmed the bypass, has been contacted for comment without response, and has given no patch timeline; no active exploitation is confirmed as of 2026-09-10.
- Impact of SYSTEM-level file reads: exposure of credentials, application secrets, private keys, registry hives (including SAM database dumps per one report) and other users' data; it does not enable code execution.
- Attribution varies by report: Chaotic Eclipse (Security Affairs), MSNightmare (GBHackers, Cyber Security News), Nightmare Eclipse (The Register, SecurityWeek); Reports 4-5 indicate the names refer to the same researcher, for whom…
- Per one report, the PoC repository contains C++ project files, a Warden.dll library and an EICAR test archive, suggesting interaction with Defender's malware-detection and file-handling workflow.
- Related releases by the same researcher: FalconFlank (CrowdStrike Falcon Sensor privilege escalation abusing the Microsoft Office malicious macro removal feature, which runs with high privileges; requires Falcon Phase 3 Optimal Protection…
Coverage timelineoldest first · each row is one article
- · 7d agoChaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day
Security Affairs· 72
Researcher Chaotic Eclipse released ShieldCrash, a PoC showing Microsoft Defender's CVE-2026-69414 patch is incomplete, enabling arbitrary file reads as SYSTEM.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". NVD description · AI analysis pending | 7.0 | 11% | PoC |
| — | |
| CVE-2026-69414 | Local Elevation of Privilege in Microsoft Defender Malware Protection Engine CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists. Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass. | 7.8 | <1% |
| masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows) |