Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

ShieldCrash: Windows Defender 0-Day PoC Bypassing ShieldBreak (CVE-2026-69414) Patch

Summary

ShieldCrash: a PoC showing Microsoft's ShieldBreak fix (CVE-2026-69414) to be incomplete, achieving arbitrary file read as SYSTEM in Windows Defender on all supported Windows versions.

Why it matters

Highlights an incomplete patch in Microsoft Defender's scanning engine, allowing local unprivileged users to weaponize antivirus file inspection routines for SYSTEM-level file access.
Vendor
Microsoft
Product
Windows Defender
Affected versions
All supported Windows versions (as of September 2026)
CVSS
7.8
Published
Collected

original ↗

Related coverage

back