Ethical Hacking News
Serial Microsoft 0-day hunter Nightmare Eclipse has dropped yet another Defender exploit, dubbed ShieldCrash, which claims to allow attackers to bypass ShieldBreak and read files as SYSTEM. This is Nightmare's 11th Microsoft zero-day, following a pattern of exploits published shortly after Microsoft's Patch Tuesday updates. The impact of this latest exploit is still being assessed by cybersecurity experts, who are urging Microsoft to take immediate action to patch ShieldCrash and prevent potential attacks.
Serial Microsoft bug hunter Nightmare Eclipse (MSNightmare) has uncovered a new zero-day exploit called ShieldCrash, which allows attackers to bypass the ShieldBreak patch and read files as SYSTEM. ShieldCrash is a bypass of an earlier Defender privilege escalation zero-day, ShieldBreak, and allows arbitrary file reads as SYSTEM, but not arbitrary writes or a full SYSTEM shell. MSNightmare's 11th Microsoft zero-day, ShieldCrash, is part of a trend of exploits that Nightmare releases shortly after Microsoft's Patch Tuesday security updates. MSNightmare has also released exploits for other security vendors' software, including a zero-day bug called FalconFlank that affects CrowdStrike's Falcon endpoint security platform.
A new zero-day exploit has been uncovered by serial Microsoft bug hunter Nightmare Eclipse, also known as MSNightmare, which claims to allow attackers to bypass the ShieldBreak patch and read files as SYSTEM. This latest exploit, dubbed ShieldCrash, follows in the footsteps of Nightmare's previous exploits, which have been consistently published shortly after Microsoft released its latest Patch Tuesday security updates.
According to Nightmare, ShieldCrash is a bypass of an earlier Defender privilege escalation zero-day, ShieldBreak (CVE-2026-69414), which allowed attackers to bypass another patch for another Nightmare Eclipse zero-day, RoguePlanet (CVE-2026-50656). Redmond patched ShieldBreak last week, and RoguePlanet in July. Both allowed attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
ShieldCrash purports to be a bypass of an earlier Defender privilege escalation zero-day, ShieldBreak, that allowed attackers to bypass another patch for another Nightmare Eclipse zero-day, RoguePlanet. The latest bypass, ShieldCrash, allows arbitrary file reads as SYSTEM - but not arbitrary writes or a full SYSTEM shell, according to the researcher. Microsoft did not immediately respond to The Register's questions, including when it planned to patch ShieldCrash. We will update this story when we hear back.
While the serial bug hunter typically finds and publishes Microsoft exploits, ShieldCrash is Nightmare's 11th Microsoft zero-day, and they have made clear that with Redmond, their vendetta is personal. They recently branched out into other security vendors' software, releasing a zero-day bug called FalconFlank that affects CrowdStrike's Falcon endpoint security platform. This one still has a Windows twist: the privilege escalation bug abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon.
Security sleuth Kevin Beaumont confirmed the FalconFlank exploit works, along with several others Nightmare released over the past couple of weeks. These include HardBreacher, a now-patched elevation of privileges bug in Kaspersky's endpoint antivirus product, and PrettyPrague, an elevation of privileges vuln in Gen Digital's Avast antivirus software.
Related Information:
https://www.ethicalhackingnews.com/articles/Serial-Microsoft-0-day-Hunter-Drops-Yet-Another-Defender-Exploit-Leaving-Cybersecurity-Experts-Reeling-ehn.shtml
https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335
Published: Wed Sep 9 13:00:47 2026 by llama3.2 3B Q4_K_M