NG Solution Team
Cybersecurity

ShieldCrash PoC Shows Microsoft Defender Zero-Day Still Exploitable After Patch

Security researcher Chaotic Eclipse has released ShieldCrash, a proof-of-concept exploit for a Microsoft Defender zero-day that the researcher says triggers an arbitrary file read as SYSTEM and demonstrates that Microsoft did not fully fix ShieldBreak (CVE-2026-69414).

ShieldCrash PoC and the remaining vulnerability

Chaotic Eclipse, also known by aliases INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, published ShieldCrash and says it can read arbitrary files with SYSTEM privileges. The researcher claims that Microsoft closed several exploitation paths for ShieldBreak but missed a specific condition that still allows the same attack. “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited,” Chaotic Eclipse wrote. “This PoC demonstrates an arbitrary file read as SYSTEM with September 2026, all supported windows versions are affected.”

Chaotic Eclipse described the released PoC as a basic version and said they may later develop it into a full SYSTEM-level exploit; for now they published only enough code to show that Microsoft’s patch does not completely block ShieldBreak.

Microsoft’s patch and advisory

Microsoft recently updated the Microsoft Malware Protection Engine to address CVE-2026-69414. The fix is included in version 1.1.26080.3, which Microsoft says requires no user action and does not affect systems with Microsoft Defender disabled. Microsoft recommends keeping malware definitions and the engine updated automatically. “Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘ShieldBreak’,” reads Microsoft’s advisory. “In response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine. In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner. For enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating.”

Other recent PoC releases by Chaotic Eclipse

Last week, Chaotic Eclipse released GreenSection, a zero-day exploit targeting Nvidia that the researcher says triggers a memory corruption flaw.

The researcher has also published other PoCs targeting anti-malware and defense products. Chaotic Eclipse released HardBreacher, a zero-day exploit targeting Kaspersky Endpoint Security that triggers a privilege escalation flaw; the researcher said the PoC is unstable and may require repeated attempts, but when successful it creates a DLL in System32 with full user permissions and that taking control of Kaspersky’s UI process can disrupt the antivirus and interfere with file-access controls, potentially leaving the system in an unstable state. Nightmare Eclipse stated the Kaspersky zero-day allows privilege escalation on a fully patched Windows 11 25H2 system running Kaspersky Endpoint v14.0.0.504.

The researcher also released PrettyPrague, a zero-day exploit targeting GenDigital Avast Antivirus that triggers a privilege escalation flaw. Chaotic Eclipse claims the PoC exploits a flaw in Avast Sandbox to dump the Windows SAM database and gain a SYSTEM-level shell, and that it reportedly works even on fully patched Avast Antivirus and Windows 11 25H2. The researcher suspects the flaw may affect other Gen Digital products including AVG and Norton.

Finally, Chaotic Eclipse published FalconFlank, a zero-day exploit targeting the CrowdStrike Falcon platform. According to the researcher, FalconFlank abuses Falcon’s “Microsoft Office file malicious macro removal” feature, a remediation function that operates with high privileges, and can be abused to escalate privileges from a low-privileged local user to a more powerful context.

Chaotic Eclipse is known for publicly releasing PoC exploits for zero-day vulnerabilities and for criticizing vendors’ handling of reports. The researcher’s releases have mainly targeted Microsoft products and some were later exploited in the wild. Notable prior disclosures include the Undefend and RedSun Defender zero-days. The releases have contributed to debate over responsible disclosure and the risks of publishing working exploits.

Related posts

AI agents go rogue in UK test: Mythos 5 and GPT‑5.6 Sol breach live internet

Jessica Williams

Is Novo Nordisk Facing Cybersecurity Challenges While Expanding in China?

David Jones

Could a cybersecurity breach impact 3 million Texas hunting and fishing license holders?

Emily Brown

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy