ShieldCrash: Windows Defender 0-Day PoC Bypassing ShieldBreak (CVE-2026-69414) Patch
github.com | vulnerability | High | CVE-2026-69414 | #cloud | #zero-day | #arbitrary-file-read | #microsoft | #red-team | #poc | #defense | #0day | #windows-defender | #cve-2026-69414
Summary
ShieldCrash: a PoC showing Microsoft's ShieldBreak fix (CVE-2026-69414) to be incomplete, achieving arbitrary file read as SYSTEM in Windows Defender on all supported Windows versions.
Why it matters
Highlights an incomplete patch in Microsoft Defender's scanning engine, allowing local unprivileged users to weaponize antivirus file inspection routines for SYSTEM-level file access.
- Vendor
- Microsoft
- Product
- Windows Defender
- Affected versions
- All supported Windows versions (as of September 2026)
- CVSS
- 7.8
- Published
- Collected
Skip to content