Nightmare Eclipse Unleashes 'ShieldCrash' Zero-Day Exploit on Fully Patched Windows Systems
A security researcher known as Nightmare Eclipse has released another zero-day exploit for Microsoft Defender, dubbed 'ShieldCrash', which targets fully patched Windows systems for privilege escalation.
The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to the researcher, who also notes that the underlying vulnerability can be exploited to gain full System privileges, allowing attackers to drop the SAM database.
This new zero-day is a bypass for ShieldBreak, another Microsoft Defender privilege escalation exploit dropped on August 2026 Patch Tuesday. However, Nightmare Eclipse claims that Microsoft's patches for ShieldBreak are incomplete and can still be exploited, releasing ShieldCrash as proof.
SOCRadar CISO Ensar Seker advises security teams to monitor Microsoft's guidance and Defender intelligence updates, enable tamper protections, restrict admin access and local execution paths, and look for any suspicious process behavior associated with Defender-related mechanisms.