Security researcher Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldCrash, capable of accessing files with SYSTEM privileges on fully patched Windows systems. The disclosure arrived immediately after Microsoft’s September 2026 Patch Tuesday updates.
ShieldCrash is a bypass for CVE-2026-69414, known as ShieldBreak, a Defender privilege-escalation vulnerability Microsoft had previously patched. ShieldBreak itself bypassed another flaw called RoguePlanet, which was disclosed in June and patched in July.
According to Nightmare Eclipse, Microsoft’s ShieldBreak fix did not completely eliminate the underlying problem. Under specific conditions, attackers can still trigger similar behavior and perform arbitrary file reads using SYSTEM privileges.
The proof-of-concept reportedly works against fully patched Windows 10, Windows 11 and Windows Server systems. However, the current version does not provide arbitrary write access, limiting what an attacker can immediately accomplish compared with a complete SYSTEM-level remote shell.
Even with that limitation, SYSTEM-level file access can expose highly sensitive information normally inaccessible to standard users. In a broader attack chain, such access could potentially help attackers obtain credentials, configuration data or other information useful for expanding a compromise.
Nightmare Eclipse described the current release as a skeleton PoC and suggested it could eventually be developed into a more complete SYSTEM exploit. This makes the vulnerability particularly relevant for defenders because additional research could increase its practical impact.
The researcher has released numerous Windows zero-days since April, targeting Microsoft Defender, BitLocker and other Windows components. These include ShieldBreak, LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma and UnDefend.
Microsoft has patched several of those vulnerabilities, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma and MiniPlasma. Other flaws disclosed by Nightmare Eclipse still lacked official fixes at the time of the ShieldCrash disclosure.
The releases are taking place amid an ongoing dispute between Nightmare Eclipse and Microsoft over bug bounty and vulnerability disclosure practices. Microsoft has also warned that it may take legal action against individuals engaging in malicious activity that causes real harm to customers.
Microsoft had not provided BleepingComputer with a response regarding ShieldCrash at the time of publication. As a result, there is currently no official patch specifically addressing the new bypass.
The discovery is particularly notable because ShieldCrash appeared after Microsoft’s latest security updates and demonstrates that the previous mitigation can still be circumvented. For organizations relying on Defender across large Windows environments, the disclosure reinforces the importance of monitoring Microsoft’s upcoming security guidance rather than assuming the earlier ShieldBreak patch completely resolved the issue.