Serial Microsoft 0-day hunter drops yet another Defender exploit
A bypass of a bypass of a bypass
Microsoft security researcher Nightmare Eclipse, also known as MSNightmare, has published a new proof-of-concept exploit for a zero-day vulnerability in Microsoft Defender called ShieldCrash. This exploit claims to allow attackers to bypass the previously patched ShieldBreak vulnerability (CVE-2026-69414) and read files as SYSTEM.
Nightmare Eclipse, a prolific Microsoft bug hunter, stated in the exploit's README that they may later develop a full SYSTEM PoC, but for now, they are releasing this skeleton PoC due to laziness. This latest bypass works on Windows systems that have already applied the September patches, which Microsoft released following the publication of ShieldCrash.
ShieldCrash is Nightmare Eclipse's 11th Microsoft zero-day exploit, and they have made it clear that they have a personal vendetta against Redmond. Recently, Nightmare Eclipse expanded their focus to other security vendors' software, releasing a zero-day bug called FalconFlank that affects CrowdStrike's endpoint security platform.
This bug abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. Other exploits recently released by Nightmare Eclipse include HardBreacher, a patched elevation of privileges bug in Kaspersky's antivirus product, and PrettyPrague, a vulnerability in Gen Digital's Avast antivirus software.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Serial Microsoft 0-day hunter drops yet another Defender exploit theregister.com