SECURITY researcher Chaotic Eclipse (INFINITE NIGHTMARE, MSNightmare, Nightmare-Eclipse) released a new zero-day exploit named ShieldCrash, a PoC that demonstrates an arbitrary file read as SYSTEM in Microsoft Defender. The PoC targets a vulnerability associated with ShieldBreak (CVE-2026-69414), which Microsoft had partially patched.
The researcher claims that, despite Microsoft’s updates, a specific condition remains exploitable and allows loading or reading arbitrary files with SYSTEM privileges across all supported Windows versions.
The disclosure follows prior Chaotic Eclipse activity exposing Defender-related flaws and other anti‑malware products. Microsoft released a Defender engine update—Malware Protection Engine version 1.1.26080.3—to fix CVE-2026-69414, with the update designed to occur automatically and without user action. The researcher asserts that the patch leaves a remaining surface where ShieldBreak can be triggered, and that ShieldCrash demonstrates this by enabling SYSTEM-level file reads under September 2026 conditions.
The article notes that ShieldCrash is described as a basic PoC for now, with potential for extension into a fuller exploit, and warns that Defender updates should be kept current to mitigate evolving threats.