SECURITY researchers have disclosed a new Microsoft Defender zero-day exploit, dubbed ShieldCrash, that can achieve full System privileges on fully patched Windows systems. The PoC reportedly demonstrates arbitrary file read at System level, with the underlying flaw capable of dropping the SAM database, according to the researcher behind the tool, Nightmare Eclipse (also known as Chaotic Eclipse, Infinite Nightmare and MSNightmare).
ShieldCrash appears to bypass prior mitigations introduced by the ShieldBreak family of Defender exploits, which were issued as patches for RoguePlanet and other chain-attack pathways.
The disclosure follows Microsoft’s Patch Tuesday cycle in September 2026, after RoguePlanet (CVE-2026-50656) was addressed in July and ShieldBreak (patched in September 2026; CVE-2026-69414) with incomplete fixes, according to Nightmare Eclipse. Security researchers, including SOCRadar’s Ensar Seker, warn that ShieldCrash highlights weaknesses in patching attack paths rather than isolated flaws.
They advise defenders to monitor Microsoft guidance and Defender intelligence updates, enable tamper protections, restrict administrative and local execution paths, and watch for suspicious Defender-related process activity. Microsoft has not yet publicly commented at press time.