securityonline.info 9 Sept 2026, 00:34 UTC

Microsoft Defender 0day PoC Exposes SYSTEM Files on Windows

Microsoft Defender 0day PoC Exposes SYSTEM Files on Windows
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Available

A publicly available 0day in Microsoft Defender, dubbed ShieldCrash, has been disclosed with a working PoC that can read arbitrary files as SYSTEM on all supported Windows versions. The flaw is associated with CVE-2026-69414 and follows an initial ShieldBreak patch for CVE-2026-6941; according to the disclosure, the original fix was incomplete and under certain conditions the issue can still be triggered. The PoC and full details are now in the public domain, lowering the barrier for attackers to study and adapt the technique.

Microsoft Defender’s Malware Protection Engine is the affected component, with the disclosure claiming the vulnerability allows elevation of privilege by obtaining SYSTEM-level access. The report notes that the PoC is described as a skeleton, suggesting potential for expansion into a full SYSTEM exploit. Affected products include all supported Windows versions running Defender as of 9 September 2026. There is no confirmed exploitation reported at the time of writing, but the public PoC elevates risk.

Defense steps emphasise monitoring for unusual SYSTEM-level file access and updating Defender or the platform to version 1.1.26080.3 as soon as it is available. Administrators are advised to follow official advisories for any new patch and to remain vigilant while public PoCs exist.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline