started · updated
Microsoft Defender zero-day exploit bypasses recent security patches
Security researcher Nightmare Eclipse has released a new zero-day exploit named ‘ShieldCrash’ that targets Microsoft Defender. The vulnerability allows for privilege escalation to SYSTEM level on fully updated versions of Windows 10, Windows 11, and Windows Server.
ShieldCrash acts as a bypass for a previous vulnerability known as ShieldBreak (CVE-2026-69414), which Microsoft had attempted to patch during its September 2026 security updates. The researcher claims that Microsoft failed to properly address the underlying issue, allowing the same problem to be triggered under specific conditions.
The current proof of concept (PoC) demonstrates arbitrary file reading with SYSTEM privileges. While the researcher has described the current PoC as a ‘skeleton,’ they have indicated the potential to develop it into a full SYSTEM access exploit in the future.
Entities
Microsoft · Microsoft Defender · Nightmare Eclipse · Windows