PoC public Microsoft Defender privilege-escalation Microsoft zero-day
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
CVE Tools coverage
Researcher Nightmare Eclipse has published the proof-of-concept code for ShieldCrash, a new zero-day vulnerability affecting Microsoft Defender on fully patched Windows systems. The exploit allows for arbitrary file reads and full System privilege escalation, serving as a bypass for previous flaws including CVE-2026-50656 (RoguePlanet) and CVE-2026-69414 (ShieldBreak). Security experts caution that the repeated ability to circumvent these fixes indicates fundamental weaknesses in how the vendor addresses the underlying attack surface.