Microsoft's Defender Patched Again, This Time by Its Own Researchers
A proof-of-concept exploit called ShieldCrash has been released by researcher Nightmare Eclipse, targeting a vulnerability in Microsoft's Defender software that was previously patched.
ShieldCrash aims to bypass Microsoft's fix for CVE-2026-69414, also known as ShieldBreak, which is a privilege-escalation flaw in the Malware Protection Engine used by Defender.
The bug allows a local attacker on a fully patched Windows 10, Windows 11, or Windows Server machine to read files as SYSTEM, even though they don't have write access.
Micrososft has not publicly confirmed ShieldCrash as a vulnerability, but the company shipped a fix for ShieldBreak just weeks before the exploit was released.