ShieldCrash Exploit Bypasses Microsoft's Patch Tuesday Fix
A notorious researcher has once again bypassed Microsoft's Patch Tuesday fix with a new Windows zero-day exploit. Nightmare Eclipse, also known as Chaotic Eclipse and Infinite Nightmare, released ShieldCrash, a proof-of-concept (PoC) that allegedly bypasses the ShieldBreak Defender patch.
The exploit allows an attacker with local code execution to read protected files as SYSTEM, giving them access to sensitive information they wouldn't normally be able to reach. The researcher claims ShieldCrash has a 100% success rate and works on Windows 11 25H2 and Windows Server 2025.
This latest exploit comes just days after Microsoft's Patch Tuesday, which addressed 966 vulnerabilities, including 105 rated 'critical' and 2 zero-days already being exploited in attacks. The researcher has a history of targeting Microsoft, having disclosed several zero-day flaws since April.