Nightmare Eclipse Unleashes ShieldCrash on Fully Patched Windows Systems
A prolific Microsoft bug hunter known as Nightmare Eclipse has released yet another exploit for Microsoft Defender. This one, called ShieldCrash, allows attackers to bypass earlier patches and read files as SYSTEM.
The researcher claims that ShieldCrash is a bypass of the earlier ShieldBreak patch, which allowed attackers to gain SYSTEM privileges on fully patched Windows systems. ShieldBreak was patched by Microsoft just last week, but Nightmare Eclipse's latest exploit can still be used to read files with elevated privileges.
This is not the first time Nightmare Eclipse has found and published a zero-day vulnerability in Microsoft Defender. In fact, this is their 11th such discovery, and they have made it clear that their goal is to expose weaknesses in Redmond's security software.