New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
The security researcher known as Nightmare Eclipse has released another Microsoft Defender zero-day exploit, right after Microsoft’s record-breaking September 2026 patches.
Dubbed ‘ShieldCrash’, the exploit targets fully patched Windows systems for privilege escalation.
The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare.
However, the underlying vulnerability can be exploited to gain full System privileges, allowing attackers to drop the SAM database, the researcher says.
Nightmare Eclipse also notes that the fresh zero-day is a bypass for ShieldBreak, the Microsoft Defender privilege escalation exploit dropped on the August 2026 Patch Tuesday.
ShieldBreak in turn was released as a bypass for Microsoft’s patches against RoguePlanet, a race condition bug dropped as a zero-day on June 2026 Patch Tuesday.
Advertisement. Scroll to continue reading.
Microsoft patched RoguePlanet(CVE-2026-50656) on July 19. It...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE