Researcher unveils new Defender zero-day that sidesteps recent patch
Zero-day researcher Nightmare Eclipse released a proof-of-concept exploit called ShieldCrash that can read files as SYSTEM on patched Windows systems, bypassing the earlier ShieldBreak fix.
Nightmare Eclipse, the prolific Microsoft-focused zero-day hunter, published a new proof-of-concept exploit dubbed ShieldCrash. The code enables attackers to read arbitrary files as the SYSTEM account on Windows 10, Windows 11 and Windows Server versions that have applied the September Patch Tuesday updates. ShieldCrash is described as a bypass of the recently patched ShieldBreak vulnerability (CVE-2026-69414), which itself had succeeded in bypassing an earlier zero-day called RoguePlanet.
Unlike its predecessors, ShieldCrash does not provide arbitrary write or a full SYSTEM shell, only file-read capability. Microsoft has not responded with a remediation timeline. The researcher, who has a history of targeting Microsoft Defender and other security products, released the exploit while also recently publishing a CrowdStrike Falcon zero-day called FalconFlank.
Why it matters
The new exploit shows that even fully patched Windows systems can still be compromised, highlighting ongoing risks for enterprises and users.
In this story
