Microsoft’s fix for a Defender privilege-escalation bug is incomplete, and the researcher who found the original flaw has published a bypass to prove it. The new proof of concept is called ShieldCrash, and it reads arbitrary files with System rights on Windows machines carrying the September 2026 patches, according to the researcher who goes by Chaotic Eclipse, also known as Nightmare Eclipse.
He says the attack can be pushed further, enough to drop the SAM database. ShieldCrash sidesteps CVE-2026-69414, the CVSS 7.8 bug he reported in August as ShieldBreak. Microsoft closed that one on September 3 by updating the Malware Protection Engine to version 1.1.26080.3. “They missed a spot where ShieldBreak can still be exploited,” he wrote.
It is the third link in a chain. RoguePlanet, CVE-2026-50656, was patched in July, ShieldBreak bypassed that in August, and ShieldCrash bypasses the follow-up.
For SOCRadar’s Ensar Seker, the pattern points to a design problem rather than a patching one. He wants teams to watch Microsoft’s advisories, switch on tamper protection and tighten who may run local executables. The same researcher has also published exploits aimed at CrowdStrike Falcon, Kaspersky, Avast and NVIDIA tools.
