ZeroHour
Story · 1 source · 1 articlefirst updated ()

ShieldCrash PoC bypasses Microsoft Defender patch for ShieldBreak (CVE-2026-69414), reads files as SYSTEM on fully patched Windows

What's new: No substantive change to the ShieldCrash story since the previous summary (2026-09-16): all four ShieldCrash reports predate it and restate the same facts - Microsoft still has not confirmed the bypass, assigned a CVE, or committed to a patch date, and no in-the-wild exploitation is reported. Attribution is clarified: 'MSNightmare' (Report 1) and 'Nightmare Eclipse' (Reports 2-3) refer to the…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Researcher Nightmare Eclipse (MSNightmare) released ShieldCrash, an 11th Microsoft zero-day PoC that bypasses the September 3, 2026 ShieldBreak fix (CVE-2026-69414) and reportedly reads arbitrary files as SYSTEM on patched Windows 10/11/Server; Microsoft has…

Zero-day researcher Nightmare Eclipse (also referenced as MSNightmare) published ShieldCrash, a proof-of-concept that allegedly enables arbitrary file reads with SYSTEM privileges on Windows 10, Windows 11, and Windows Server systems running Microsoft's September 3, 2026 patches. ShieldCrash bypasses the fix for ShieldBreak (CVE-2026-69414), a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine; that fix had itself bypassed patches for the RoguePlanet race condition (CVE-2026-50656), making ShieldCrash the third bypass in the series and suggesting incomplete patching of the underlying attack path. The read primitive can expose configuration files, credentials, private keys, other users' data, and the SAM database, but does not enable arbitrary writes, code execution, or a full SYSTEM shell. The PoC repository contains C++ project files, a Warden.dll library, and an EICAR test archive, consistent with interaction with Defender's malware-detection and file-handling workflow. Microsoft has not confirmed the bypass, assigned a CVE to ShieldCrash, or given a patch timeline, and in-the-wild exploitation is not reported (exploitation status and affected versions are not detailed). ShieldCrash is the researcher's 11th Microsoft zero-day; recent releases also targeted CrowdStrike Falcon (FalconFlank), Kaspersky endpoint antivirus (HardBreacher, patched), and Avast (PrettyPrague), several of which Kevin Beaumont independently confirmed work as described. Advised mitigations: enable Defender tamper protection, restrict admin access, monitor Defender-related process behavior, and watch for unsigned DLLs touching Defender paths.

  • ShieldCrash is a proof-of-concept zero-day enabling arbitrary file reads with SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server; it does not enable arbitrary writes, code execution, or a full SYSTEM shell…
  • It bypasses Microsoft's September 3, 2026 fixes for ShieldBreak (CVE-2026-69414), a high-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender (Reports 3-4).
  • The ShieldBreak fix had itself bypassed patches for the RoguePlanet race condition (CVE-2026-50656); ShieldCrash is the third bypass in the series (Reports 2-3).
  • The PoC can dump the SAM database; a successful read could expose configuration files, credentials, private keys, and other users' data (Reports 1, 3).
  • The PoC repository contains C++ project files, a Warden.dll library, and an EICAR test archive, suggesting interaction with Defender's malware-detection and file-handling workflow (Report 1).
  • ShieldCrash has no CVE assignment; Microsoft has not confirmed the bypass or responded on a patch timeline; in-the-wild exploitation is not reported and affected versions are not detailed (Reports 1-4).
  • ShieldCrash is Nightmare Eclipse's 11th Microsoft zero-day; other recent releases include FalconFlank (CrowdStrike Falcon), HardBreacher (Kaspersky, patched), and PrettyPrague (Avast); Kevin Beaumont confirmed several, including…
  • Recommended mitigations: enable Defender tamper protection, restrict admin access, monitor Defender-related process behavior, and watch for unsigned DLLs touching Defender paths (Reports 1, 3).

Coverage timeline

  1. · 7d ago
    Cyber Security News· 45
    New Windows Defender ShieldCrash 0-Day Bypasses Microsoft Patch to Read Files as SYSTEM

    Researcher's ShieldCrash PoC claims Microsoft Defender still allows arbitrary file reads as SYSTEM on patched Windows, bypassing the CVE-2026-69414 fix.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50656
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

NVD description · AI analysis pending
7.011% PoC
  • microsoft malware protection engine
CVE-2026-69414
Local Elevation of Privilege in Microsoft Defender Malware Protection Engine

CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists.

Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass.

7.8<1%
  • Microsoft Malware Protection Engine (used in Microsoft Defender)
masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows)