SECURITY Signal 51
New ShieldCrash Defender zero-day reads files as SYSTEM on patched Windows
Researcher Nightmare Eclipse released ShieldCrash, a Microsoft Defender zero-day that bypasses the previous ShieldBreak patch to read files as SYSTEM on fully patched Windows systems.
This represents the third iteration in a chain of privilege escalation bypasses targeting Microsoft Defender, demonstrating a persistent weakness even in systems applying the latest September patches. Administrators face continued exposure to SYSTEM-level file reads until Microsoft releases a patch for ShieldCrash.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
ShieldCrash allows attackers to read arbitrary files as SYSTEM on Windows systems that have applied the September patches.
The exploit bypasses the patch for ShieldBreak (CVE-2026-69414), which itself bypassed the patch for RoguePlanet (CVE-2026-50656).
The released skeleton proof-of-concept does not allow arbitrary writes or a full SYSTEM shell, though the researcher may rework it later.
THE CLUSTER