New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
A new zero-day exploit, dubbed ‘ShieldCrash’, targeting fully patched Windows systems has been released by security researcher Nightmare Eclipse. This exploit allows for privilege escalation and dropping the SAM database, bypassing existing Microsoft Defender patches and previous exploits like ShieldBreak and RoguePlanet. Microsoft has acknowledged the issue and released patches, but the researcher claims the fixes are incomplete and the vulnerability remains exploitable.
A new zero-day exploit, dubbed ‘ShieldCrash’, targeting fully patched Windows systems has been released by security researcher Nightmare Eclipse. This exploit allows for privilege escalation and dropping the SAM database, bypassing existing Microsoft Defender patches and previous exploits like ShieldBreak and RoguePlanet. Microsoft has acknowledged the issue and released patches, but the researcher claims the fixes are incomplete and the vulnerability remains exploitable.
Nightmare Eclipse notes that the fresh zero-day is a bypass for ShieldBreak, the Microsoft Defender privilege escalation exploit dropped on the August 2026 Patch Tuesday. ShieldBreak in turn was released as a bypass for Microsoft’s patches against RoguePlanet, a race condition bug dropped as a zero-day on June 2026 Patch Tuesday. Microsoft patched RoguePlanet (CVE-2026-50656) on July 19. It acknowledged ShieldBreak on August 14 and rolled out fixes for it on September 3. The bug is tracked as CVE-2026-69414.
Nightmare Eclipse says that Microsoft’s patches for ShieldBreak are incomplete, and that the security defect can still be exploited, releasing ShieldCrash as proof. According to SOCRadar CISO Ensar Seker, ShieldCrash raises concerns mainly because it exposes a weakness in Microsoft’s patching of the underlying vulnerability’s attack paths. "When researchers can bypass successive fixes for RoguePlanet and ShieldBreak, it suggests the underlying security boundary or attack surface may require a more comprehensive redesign rather than another narrowly targeted patch," Seker said. He advises security teams to monitor Microsoft’s guidance and Defender intelligence updates, enable tamper protections, restrict admin access and local execution paths, and look for any suspicious process behavior associated with Defender-related mechanisms. "Microsoft should also assess the complete vulnerability class and related code paths, not only the specific condition demonstrated by this latest proof of concept," Seker added.