Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

Nightmare Eclipse drops ShieldCrash zero‑day bypassing defender patches.

A new exploit called ShieldCrash targets fully patched Windows systems for privilege escalation, allowing arbitrary file reads and potential access to the SAM database. The researcher says it bypasses Microsoft’s fixes for ShieldBreak, which itself was a bypass for the earlier RoguePlanet race condition, highlighting repeated gaps in patch coverage. Security experts warn that successive bypasses suggest deeper flaws in Defender’s underlying attack surface that require broader redesign. They advise monitoring Defender updates, tightening admin controls and watching for suspicious processes tied to Defender mechanisms.

Read more:

https://www.securityweek.com/new-shieldcrash-zero-day-exploit-targets-microsoft-defender/