Windows Defender Bypass Allows Attackers to Read Sensitive Files
A researcher has discovered a new vulnerability in Windows Defender, allowing an attacker to read files with SYSTEM-level privileges on fully updated and supported Windows systems.
The issue, dubbed ShieldCrash, bypasses Microsoft's earlier fix for ShieldBreak (CVE-2026-69414) and can potentially expose sensitive data such as application configuration files, credentials, security product settings, and private keys.
The researcher claims that the vulnerability is significant because it allows an attacker to access protected files without needing to escalate privileges.