ShieldCrash zero-day targets Microsoft Defender on patched Windows

Nightmare Eclipse published ShieldCrash, a zero-day PoC that reads files as System on patched Windows and can escalate to full System privileges while bypassing ShieldBreak fixes.

A security researcher known as Nightmare Eclipse released a new zero-day exploit called ShieldCrash that targets Microsoft Defender on fully patched Windows machines. The researcher posted the proof-of-concept in the days after Microsoft issued its large September 2026 security updates.

According to the researcher, ShieldCrash demonstrates an arbitrary file read at the System privilege level. The PoC can be extended to drop the Security Account Manager (SAM) database, which would let an attacker gain full System privileges on a vulnerable device.

Nightmare Eclipse, who also uses aliases including Chaotic Eclipse, Infinite Nightmare and MSNightmare, described ShieldCrash as a bypass for ShieldBreak. ShieldBreak was published in August 2026 as a way to bypass earlier fixes for a race condition tracked as RoguePlanet.

Microsoft patched RoguePlanet, tracked as CVE-2026-50656, on July 19, 2026. The company acknowledged ShieldBreak on August 14 and released fixes for it on September 3 under CVE-2026-69414. The researcher says the September fixes remain incomplete and that ShieldCrash shows additional attack paths still exist.

Ensar Seker, CISO at SOCRadar, warned that repeated bypasses point to gaps in the patched attack paths and recommended specific defensive steps. “When successive fixes for RoguePlanet and ShieldBreak can be bypassed, the affected code paths and security boundary should be assessed more broadly rather than patched repeatedly for single conditions,” he said. He advised teams to follow Microsoft’s Defender intelligence updates, enable tamper protection, restrict administrative access and local execution paths, and monitor for suspicious process behavior tied to Defender components.

The PoC focuses on achieving an arbitrary file read as System, but the code and description indicate it can be escalated to full System control. If an attacker used the exploit to that extent they could extract credential stores such as the SAM database and execute code with the highest local privileges.

Nightmare Eclipse has previously published proofs-of-concept and exploits affecting other vendors, including CrowdStrike, Nvidia and Avast. Microsoft did not immediately respond to requests for comment.

Security teams running Microsoft Defender on Windows should review Microsoft’s guidance and available mitigations, enable recommended protections, and harden administrative controls while awaiting further details and any official fixes.

Articles by this author