A publicly available 0day in Microsoft Defender, dubbed ShieldCrash, has been disclosed with a working PoC that can read arbitrary files as SYSTEM on all supported Windows versions. The flaw is associated with CVE-2026-69414 and follows an initial ShieldBreak patch for CVE-2026-6941; according to the disclosure, the original fix was incomplete and under certain conditions the issue can still be triggered. The PoC and full details are now in the public domain, lowering the barrier for attackers to study and adapt the technique.
Microsoft Defender’s Malware Protection Engine is the affected component, with the disclosure claiming the vulnerability allows elevation of privilege by obtaining SYSTEM-level access. The report notes that the PoC is described as a skeleton, suggesting potential for expansion into a full SYSTEM exploit. Affected products include all supported Windows versions running Defender as of 9 September 2026. There is no confirmed exploitation reported at the time of writing, but the public PoC elevates risk.
Defense steps emphasise monitoring for unusual SYSTEM-level file access and updating Defender or the platform to version 1.1.26080.3 as soon as it is available. Administrators are advised to follow official advisories for any new patch and to remain vigilant while public PoCs exist.