Windows Defender ShieldCrash Bypass Allows File Reads as SYSTEM
A vulnerability has been discovered in Microsoft's Windows Defender that allows an attacker to read files as SYSTEM, despite a previous patch for ShieldBreak (CVE-2026-69414). The issue was found by researcher MSNightmare and is being referred to as ShieldCrash.
The vulnerability could allow an attacker to access sensitive data such as application configuration files, credential-related material, security product settings, private keys, browser or service secrets, or files belonging to other Windows users. This is significant because the SYSTEM account has broader permissions than normal users and most administrator accounts.
The researcher claims that Microsoft's fix for ShieldBreak did not fully address the underlying issue, allowing arbitrary file reads as SYSTEM on patched Windows systems. However, it is worth noting that this is a researcher-reported claim pending independent reproduction or a Microsoft security advisory.