New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Microsoft Defender

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates.

ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in June and patched by Microsoft in July.

According to Nightmare Eclipse, the ShieldCrash proof-of-concept exploit lets attackers gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems, but will not give them write access to the compromised systems.

"Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited," they said.

"This PoC demonstrates an arbitrary file read as SYSTEM with September 2026, all supported windows versions are affected. I might rework this later into a full SYSTEM PoC but for now I'm dropping this skeleton PoC because I'm feeling a bit lazy."

Nightmare Eclipse ShieldCrash Defender zero-day

Nightmare Eclipse released these zero-day exploits as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices.

Microsoft responded with warnings of legal action against anyone engaging in "malicious activity causing real harm" to its customers, prompting many to believe that the company was directly threatening the security researcher.

Since April, the anonymous security researcher has disclosed a long string of zero-day flaws, including the ShieldBreak, LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend zero-days targeting Microsoft Defender, BitLocker, and other Windows components.

While Microsoft fixed the ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws, the other vulnerabilities disclosed by Nightmare Eclipse still lack an official patch.

A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out earlier today about the ShieldCrash zero-day.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report
source: BleepingComputer