securityaffairs.com 9 Sept 2026, 07:53 UTC

ShieldCrash PoC Revives Microsoft Defender SYSTEM File Read Flaw

ShieldCrash PoC Revives Microsoft Defender SYSTEM File Read Flaw
CyberSIXT Evidence Panel Source marked as original reporting
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

SECURITY researcher Chaotic Eclipse (INFINITE NIGHTMARE, MSNightmare, Nightmare-Eclipse) released a new zero-day exploit named ShieldCrash, a PoC that demonstrates an arbitrary file read as SYSTEM in Microsoft Defender. The PoC targets a vulnerability associated with ShieldBreak (CVE-2026-69414), which Microsoft had partially patched.

The researcher claims that, despite Microsoft’s updates, a specific condition remains exploitable and allows loading or reading arbitrary files with SYSTEM privileges across all supported Windows versions.

The disclosure follows prior Chaotic Eclipse activity exposing Defender-related flaws and other anti‑malware products. Microsoft released a Defender engine update—Malware Protection Engine version 1.1.26080.3—to fix CVE-2026-69414, with the update designed to occur automatically and without user action. The researcher asserts that the patch leaves a remaining surface where ShieldBreak can be triggered, and that ShieldCrash demonstrates this by enabling SYSTEM-level file reads under September 2026 conditions.

The article notes that ShieldCrash is described as a basic PoC for now, with potential for extension into a fuller exploit, and warns that Defender updates should be kept current to mitigate evolving threats.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline