A new zero-day exploit has been released by an anonymous security researcher, Nightmare Eclipse, that can grant SYSTEM access on fully patched Windows systems. The exploit, called ShieldCrash, bypasses a previously patched flaw in Microsoft Defender known as ShieldBreak, which itself was a fix for another issue disclosed in June.
The ShieldCrash proof-of-concept exploit works by taking advantage of an oversight in the patching process, allowing attackers to gain SYSTEM privileges on Windows 10, Windows 11, and Windows Server systems. However, it does not grant write access to the compromised system. Nightmare Eclipse released the zero-day as part of a long-standing dispute with Microsoft over its bug bounty and vulnerability disclosure practices.
This latest exploit is particularly concerning because it affects all supported versions of Windows, including fully patched systems that were thought to be secure. Microsoft had previously fixed several issues related to ShieldBreak, but it appears they missed a key spot where the problem could still be exploited. Nightmare Eclipse has stated that while this proof-of-concept does not grant SYSTEM write access, it can still read arbitrary files as SYSTEM.
The release of ShieldCrash is just the latest in a string of zero-day exploits targeting Microsoft Defender and other Windows components, including BitLocker. These exploits have been disclosed by Nightmare Eclipse over the past few months, but many remain unpatched. Microsoft has responded to the latest exploit with warnings of legal action against anyone engaging in “malicious activity causing real harm” to its customers.
While this may seem like a veiled threat against the security researcher themselves, it’s worth noting that Nightmare Eclipse has been releasing these exploits as part of their ongoing criticism of Microsoft’s bug bounty and vulnerability disclosure practices. The company has previously responded to similar disclosures with promises to improve its patching process and engage more openly with the security research community.
For users, this exploit highlights the importance of keeping software up-to-date and being cautious when using valid credentials. Even with fully patched systems, attackers can still gain access if they know how to exploit specific vulnerabilities. The best defense against these types of attacks is a combination of robust security measures, including multi-factor authentication, regular backups, and staying informed about the latest threats.
As we’ve seen with this latest exploit, even the most secure-looking systems are not immune to attack. Users should remain vigilant and take steps to protect themselves from potential threats. This includes regularly reviewing system logs for suspicious activity, keeping software and firmware up-to-date, and using reputable security tools to detect and respond to attacks. By staying informed and taking proactive measures, users can reduce their risk of falling victim to these types of exploits.
Source: Bleeping Computer — 2026-09-09