Nightmare Eclipse's Zero-Day Wave: Defender 'ShieldCrash' Patch Bypass Tops CrowdStrike, Avast, and NVIDIA PoCs
In early September 2026, a researcher identified as Nightmare Eclipse (also Chaotic Eclipse / MSNightmare) released zero-day PoCs against Microsoft Defender (ShieldCrash, which bypasses the CVE-2026-69414 ShieldBreak fix), CrowdStrike Falcon (FalconFlank),…
Between September 7 and 10, 2026, a prolific zero-day researcher — called Nightmare Eclipse by SecurityWeek and The Register, Chaotic Eclipse by Security Affairs, and MSNightmare by GBHackers and Cyber Security News, apparently the same person — published a series of privilege-escalation PoCs against major security products. The most consequential, ShieldCrash, bypasses Microsoft's September 3 fix for CVE-2026-69414 (ShieldBreak), a high-severity elevation-of-privilege flaw in the Microsoft Malware Protection Engine. The PoC demonstrates arbitrary file reads with SYSTEM privileges on all supported Windows versions (Windows 10, Windows 11, Windows Server) even with the September 2026 updates and engine version 1.1.26080.3 applied, including dumping the SAM database; it does not enable arbitrary writes, code execution, or a full SYSTEM shell. No CVE is assigned, Microsoft has not confirmed the bypass nor given a patch timeline, and it is the researcher's 11th Microsoft zero-day and the third bypass in a chain in which ShieldBreak (CVE-2026-69414) itself bypassed the RoguePlanet (CVE-2026-50656) race-condition fix. Earlier in the window the researcher released FalconFlank, a CrowdStrike Falcon Sensor privilege escalation abusing the Microsoft Office File Suspicious Macro Removal remediation feature (which runs with high privileges) on fully updated Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection; CrowdStrike is investigating and advises disabling that policy. PrettyPrague elevates privileges via the Avast sandbox, dumping the SAM database for a SYSTEM shell, possibly affecting other Gen Digital products (AVG, Norton); GenDigital says it is fixed. GreenSection exploits an out-of-bounds write in a shared NVIDIA global memory section (\BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba}) with full read/write access to all users; the unstable PoC crashes Vulkan/OpenGL applications and could potentially compromise dwm.exe, though impact was not fully assessed; NVIDIA is actively investigating. The researcher's prior Kaspersky zero-day, HardBreacher, was patched August 31. Kevin Beaumont reported the Avast, CrowdStrike, and Kaspersky exploits work, confirming FalconFlank and HardBreacher as described. No active exploitation has been reported.
- Researcher naming differs across sources: SecurityWeek/The Register say 'Nightmare Eclipse', Security Affairs says 'Chaotic Eclipse', GBHackers/Cyber Security News say 'MSNightmare'; Security Affairs and The Register indicate these are…
- ShieldCrash bypasses Microsoft's September 3, 2026 fix for CVE-2026-69414 (ShieldBreak), a high-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender.
- ShieldCrash impact: arbitrary file reads with SYSTEM privileges on all supported Windows versions (Windows 10, Windows 11, Windows Server) even after September 2026 updates and with Malware Protection Engine version 1.1.26080.3; can dump…
- Bypass chain: ShieldCrash bypassed the ShieldBreak patch (CVE-2026-69414), which itself bypassed the RoguePlanet fix (CVE-2026-50656) — the third bypass of the same underlying attack path per SecurityWeek.
- ShieldCrash is the researcher's 11th Microsoft zero-day; Microsoft has not confirmed the bypass and has not provided a patch timeline; no active exploitation has been confirmed; the PoC repository reportedly contains C++ project files, a…
- FalconFlank: zero-day privilege escalation in CrowdStrike Falcon Sensor abusing the Microsoft Office File Suspicious Macro Removal remediation feature, which runs with high privileges; works on fully updated Windows 11 25H2 and Windows…
- CrowdStrike response (per Security Affairs): investigating and advising customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy, with customers still protected by Cloud Anti-malware for Microsoft Office…
- PrettyPrague: privilege escalation via the Avast sandbox that dumps the SAM database for a SYSTEM shell; possibly affects other Gen Digital products including AVG and Norton; GenDigital states it has fixed the issue.
Coverage timelineoldest first · each row is one article
- · 9d agoNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
SecurityWeek· 62
Researcher Nightmare Eclipse released working zero-day PoCs for Avast, CrowdStrike Falcon, and Nvidia, prompting a Gen patch, CrowdStrike mitigation, and Nvidia investigation.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". NVD description · AI analysis pending | 7.0 | 11% | PoC |
| — | |
| CVE-2026-69414 | Local Elevation of Privilege in Microsoft Defender Malware Protection Engine CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists. Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass. | 7.8 | <1% |
| masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows) |