Microsoft Defender Zero-Day 'ShieldCrash' Allows SYSTEM-Level File Reads
A prolific zero-day researcher has released a proof-of-concept exploit for a new Microsoft Defender vulnerability, 'ShieldCrash,' which bypasses a previous patch and allows SYSTEM-level file access.

Zero-day researcher Nightmare Eclipse, known for their persistent focus on Microsoft vulnerabilities, has unveiled a new proof-of-concept exploit for a zero-day dubbed ShieldCrash. This exploit targets Microsoft Defender and reportedly allows attackers to read files with SYSTEM privileges on fully patched Windows systems. The researcher claims ShieldCrash bypasses the patch for a previous Defender zero-day, ShieldBreak (CVE-2026-69414), which itself was a patch for another vulnerability, RoguePlanet (CVE-2026-50656), also discovered by Nightmare Eclipse.
Nightmare Eclipse published the ShieldCrash exploit shortly after Microsoft's September Patch Tuesday updates were released. According to the researcher's README, the exploit works even on systems that have applied these latest security patches. While the previous vulnerabilities, ShieldBreak and RoguePlanet, allowed for privilege escalation to SYSTEM, ShieldCrash is described as enabling arbitrary file reads as SYSTEM, rather than full SYSTEM shell access or arbitrary writes. This distinction is crucial, as it limits the immediate impact but still poses a significant risk for data exfiltration.
Microsoft has not yet responded to requests for comment regarding ShieldCrash, including information on when a patch might be expected. This latest discovery continues a pattern for Nightmare Eclipse, who has now released eleven zero-day exploits targeting Microsoft products. The researcher has previously stated that their focus on Microsoft is a personal vendetta, highlighting a deep-seated adversarial relationship.
While Nightmare Eclipse primarily targets Microsoft software, they have recently expanded their focus to other security vendors. Last week, the researcher released an exploit for CrowdStrike's Falcon endpoint security platform, named FalconFlank. This vulnerability, while affecting CrowdStrike, also leveraged a Microsoft Office feature related to malicious macro remediation, demonstrating a complex interplay between different security products and underlying operating system components.
Security experts have begun to confirm the efficacy of Nightmare Eclipse's recent findings. Kevin Beaumont, a security researcher, has verified the FalconFlank exploit and several other recent disclosures. These include HardBreacher, a now-patched privilege escalation bug in Kaspersky's endpoint antivirus, and PrettyPrague, a similar vulnerability in Gen Digital's Avast antivirus software. This broader range of targets indicates a widening scope for the researcher's activities.
The implications of ShieldCrash are significant for organizations relying on Microsoft Defender for endpoint protection. The ability for an attacker to read arbitrary files as SYSTEM on a fully patched system could lead to the exposure of sensitive configuration data, credentials, or other critical information. While not a full remote code execution vulnerability, it represents a substantial step in an attack chain, potentially enabling further lateral movement or data theft.
This incident underscores the ongoing challenge of zero-day vulnerabilities, particularly those targeting core security software like antivirus solutions. The rapid pace at which new exploits are discovered and released, often shortly after patches are deployed for previous vulnerabilities, puts a continuous strain on security teams to maintain robust defenses and rapid patching cycles. The actions of researchers like Nightmare Eclipse, while contributing to security awareness, also highlight the persistent cat-and-mouse game between vulnerability discovery and exploitation.