Serial Microsoft 0-day hunter drops yet another Defender exploit
- ID
- 22953
- Status
- summarized
- Published
- 10 Sep 2026, 1:23 AM
- Fetched
- 10 Sep 2026, 5:22 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 10 Sep 2026, 5:25 AM
- Tags
- Audience
- developerssaas_founders
What happened
Researcher Nightmare Eclipse published their 11th Microsoft zero-day, a Defender exploit called ShieldCrash that bypasses last week's ShieldBreak patch (CVE-2026-69414), which itself patched an earlier zero-day called RoguePlanet (CVE-2026-50656). ShieldCrash allows arbitrary file reads as SYSTEM on fully patched Windows 10, 11, and Server systems, though not arbitrary writes or a full SYSTEM shell. Microsoft has not yet responded with a patch timeline.
Why it matters
If you run Windows endpoints in production, this is the third link in a chain of Defender privilege escalation bypasses on fully patched systems within three months — assume file-read-as-SYSTEM exposure on any Windows machine until Microsoft patches ShieldCrash, and avoid storing secrets in files readable by SYSTEM on Windows hosts.
Discussion angle
The cat-and-mouse pattern of patch-bypass-of-patch-bypass raises whether Windows Defender's architecture makes this cycle structurally inevitable, and what that means for teams relying on it as their primary endpoint control.