logo

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

ID: ccf648df-a7a9-5d0a-b799-6836da0e5dd6

STIX ID: report--ccf648df-a7a9-5d0a-b799-6836da0e5dd6

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-09-09

Date Updated: 2026-09-10

Author: Sergiu Gatlan

...
...

An anonymous researcher calling themselves Nightmare Eclipse released 'ShieldCrash', a proof-of-concept exploit that re-exploits a patched Microsoft Defender privilege escalation (ShieldBreak) to obtain SYSTEM arbitrary file read on fully patched Windows 10/11 and Windows Server; the researcher has disclosed numerous recent Defender zero-days, some of which remain unpatched, and Microsoft has responded with warnings about potential legal action.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.