Nightmare Eclipse releases ShieldCrash, an 11th Microsoft zero-day bypassing the Defender patch for CVE-2026-69414, alongside CrowdStrike FalconFlank PoC
Researcher Nightmare Eclipse (aka Chaotic Eclipse / MSNightmare) published ShieldCrash, a proof-of-concept that bypasses Microsoft's September 2026 ShieldBreak patch (CVE-2026-69414) and reads files as SYSTEM on fully patched Windows 10/11/Server; the same…
Security researcher Nightmare Eclipse — also referred to as Chaotic Eclipse (Security Affairs) or MSNightmare (The Register) — released ShieldCrash, a proof-of-concept zero-day against Microsoft Defender and the researcher's 11th Microsoft zero-day. ShieldCrash bypasses Microsoft's September 3, 2026 fixes for ShieldBreak (CVE-2026-69414), a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine; ShieldBreak itself had bypassed the patch for the RoguePlanet race condition (CVE-2026-50656), making ShieldCrash the third bypass in the series and suggesting Microsoft's patching of the underlying attack path is incomplete. The PoC works on Windows 10, Windows 11, and Windows Server systems with the September 2026 patches applied, enables arbitrary file reads with SYSTEM privileges, and can be used to dump the SAM database; The Register notes no arbitrary write or full SYSTEM shell has been demonstrated. Microsoft has been contacted and has not said when it plans to patch, and SOCRadar reports that exploitation in real attacks and affected versions are not detailed. Kevin Beaumont confirmed several of the researcher's recent exploits, including FalconFlank and HardBreacher, work as described. In related releases, the researcher published FalconFlank, a privilege escalation PoC against CrowdStrike Falcon Sensor that abuses the Microsoft Office malicious macro removal remediation feature, which runs with high privileges; it requires Falcon Phase 3 Optimal Protection with the feature enabled and works on fully updated Windows 11 25H2 and Windows Server 2025. CrowdStrike says it is investigating and advises customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy while remaining protected by Cloud Anti-malware for Microsoft Office Files. The researcher also released HardBreacher against Kaspersky Endpoint Security (reported patched by The Register) and PrettyPrague against Gen Digital's Avast, which dumps the SAM database for a SYSTEM shell and, per Security Affairs, may extend to AVG and Norton. Security Affairs notes the series highlights that EDR elevated privileges can become a local privilege escalation attack surface, and SecurityWeek reports experts advise enabling Defender tamper protection, restricting admin access, and monitoring Defender-related process behavior.
- ShieldCrash is a Microsoft Defender zero-day PoC by Nightmare Eclipse (aliases: Chaotic Eclipse, MSNightmare) and is the researcher's 11th published Microsoft zero-day.
- ShieldCrash bypasses Microsoft's September 3, 2026 fixes for ShieldBreak (CVE-2026-69414), a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine (SOCRadar).
- CVE-2026-69414 (ShieldBreak) had itself bypassed the patch for RoguePlanet (CVE-2026-50656), a race condition; ShieldCrash is the third bypass in the series, suggesting incomplete patching of the underlying attack path.
- ShieldCrash works on Windows 10, Windows 11, and Windows Server with the September 2026 patches applied, enables arbitrary file reads as SYSTEM, and can dump the SAM database; no arbitrary write or full SYSTEM shell has been demonstrated,…
- Microsoft has not responded on a patch timeline for ShieldCrash; SOCRadar notes exploitation status and affected versions are not detailed in available reporting.
- FalconFlank is a privilege escalation PoC against CrowdStrike Falcon Sensor that abuses the Microsoft Office file malicious macro removal remediation feature, which operates with high privileges; it requires Falcon Phase 3 Optimal…
- CrowdStrike is investigating FalconFlank and advises disabling the Microsoft Office File Suspicious Macro Removal Windows policy; customers remain protected by Cloud Anti-malware for Microsoft Office Files.
- The same researcher recently released HardBreacher against Kaspersky Endpoint Security (reported patched by The Register) and PrettyPrague against Gen Digital's Avast, which dumps the SAM database for a SYSTEM shell; Security Affairs…
Coverage timelineoldest first · each row is one article
- · 6d agoChaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank
Security Affairs· 72
Researcher Chaotic Eclipse released FalconFlank, a PoC zero-day privilege escalation exploit against CrowdStrike Falcon's Microsoft Office macro removal feature.
- · 6d agoSerial Microsoft 0-day hunter drops yet another Defender exploit
The Register · Security· 55
Researcher Nightmare Eclipse released ShieldCrash, a Microsoft Defender zero-day PoC that bypasses September patches and reads files as SYSTEM.
- · 6d agoNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
SecurityWeek· 65
Researcher Nightmare Eclipse released ShieldCrash, a Microsoft Defender zero-day PoC bypassing ShieldBreak patches to gain System privileges on Windows.
- · 5d agoShieldCrash PoC: Microsoft Defender Fix Bypass
SOCRadar· 62
A ShieldCrash proof-of-concept bypasses Microsoft's patch for CVE-2026-69414, a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". NVD description · AI analysis pending | 7.0 | 11% | PoC |
| — | |
| CVE-2026-69414 | Local Elevation of Privilege in Microsoft Defender Malware Protection Engine CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists. Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass. | 7.8 | <1% |
| masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows) |