thehackernews.com 9 Sept 2026, 06:47 UTC

Microsoft Defender Zero Day Bypasses Patch to Read Windows Files as SYSTEM

CyberSIXT Evidence Panel Source marked as original reporting
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A security researcher going by Chaotic Eclipse has released a proof-of-concept demonstrating a new zero-day in Microsoft Defender, named ShieldCrash. The PoC suggests it bypasses the previously patched ShieldBreak vulnerability, CVE-2026-69414 (CVSS 7.8), by exploiting a remaining flaw under certain conditions. The researcher claims that, despite Microsoft’s updates to mitigate ShieldBreak, a specific vulnerability spot was missed that can still be exploited to trigger the same underlying problem.

The demonstration reportedly enables an attacker to read arbitrary files with SYSTEM privileges on Windows, affecting all supported desktop Windows versions. Microsoft notes that the corresponding fix for CVE-2026-69414 was delivered via the Microsoft Malware Protection Engine update, version 1.1.26080.3, and that this does not require customer action. The company adds that automatic updates help keep protections current, and systems where Defender is disabled are unaffected.

The ongoing disclosures follow Chaotic Eclipse’s recent activity, including PoC exploits for other vendor products, and reflect a rapidly evolving threat landscape where even patched issues can present residual risk if patches leave edge cases unaddressed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline