Researcher releases Microsoft Defender bypass days after patch

← Back to the feed

Researcher releases Microsoft Defender bypass days after patch

The Register · 6 hours ago

Security researcher Nightmare Eclipse, also known as MSNightmare, has released another proof-of-concept exploit targeting Microsoft Defender, this time for a flaw dubbed ShieldCrash that bypasses a patch issued only last week. The exploit reportedly allows attackers to read files with SYSTEM-level privileges even on Windows machines that have installed September's Patch Tuesday updates, continuing the researcher's pattern of publishing new bugs almost immediately after Microsoft ships fixes. This matters because it exposes an ongoing weakness in Defender's privilege protections and puts pressure on Microsoft to respond quickly, though the company has not yet said when a fix will arrive.

ShieldCrash is a bypass of ShieldBreak (CVE-2026-69414), itself a bypass of an earlier flaw called RoguePlanet (CVE-2026-50656); Microsoft patched RoguePlanet in July and ShieldBreak just last week. Nightmare describes ShieldCrash as a "skeleton" proof-of-concept limited to arbitrary file reads rather than full SYSTEM control, and it is the researcher's eleventh Microsoft zero-day, part of what they have called a personal vendetta against the company. They have also recently branched out to other vendors, publishing exploits affecting CrowdStrike Falcon, Kaspersky and Avast, with several confirmed working by security researcher Kevin Beaumont.

  • Researcher drops new Defender SYSTEM-privilege exploit, ShieldCrash, bypassing a patch from last week
  • It's the researcher's 11th Microsoft zero-day; Microsoft hasn't confirmed a patch timeline
  • Same researcher recently hit CrowdStrike, Kaspersky and Avast with separate exploits

Software

Read the full article at the source →

Originally published by The Register as “Serial Microsoft 0-day hunter drops yet another Defender exploit”.