A security researcher going by Chaotic Eclipse has released a proof-of-concept demonstrating a new zero-day in Microsoft Defender, named ShieldCrash. The PoC suggests it bypasses the previously patched ShieldBreak vulnerability, CVE-2026-69414 (CVSS 7.8), by exploiting a remaining flaw under certain conditions. The researcher claims that, despite Microsoft’s updates to mitigate ShieldBreak, a specific vulnerability spot was missed that can still be exploited to trigger the same underlying problem.
The demonstration reportedly enables an attacker to read arbitrary files with SYSTEM privileges on Windows, affecting all supported desktop Windows versions. Microsoft notes that the corresponding fix for CVE-2026-69414 was delivered via the Microsoft Malware Protection Engine update, version 1.1.26080.3, and that this does not require customer action. The company adds that automatic updates help keep protections current, and systems where Defender is disabled are unaffected.
The ongoing disclosures follow Chaotic Eclipse’s recent activity, including PoC exploits for other vendor products, and reflect a rapidly evolving threat landscape where even patched issues can present residual risk if patches leave edge cases unaddressed.