preloader

· · digital-security devops microsoft windows windows-defender cve vulnerability-management patch-management zero-day europe

Microsoft’s Patch for Its Own Antivirus Flaw Has Now Failed Twice

Source: SecurityWeek

Microsoft used its September Patch Tuesday to close a Windows Defender flaw it had been sitting on since August. Two hours later, the same researcher who found that flaw published proof that the fix does not hold.

The third round of the same fight

In June we covered RoguePlanet, a Windows Defender privilege escalation bug credited to a researcher going by Nightmare Eclipse. In August, after Microsoft’s patch for that bug turned out to leave a different path open, the same researcher, also using the handles Chaotic Eclipse and MSNightmare, published ShieldBreak, tracked as CVE-2026-69414. Microsoft finally shipped a fix for ShieldBreak as part of its September 2026 Patch Tuesday. The researcher’s response, published within hours, was a new proof of concept called ShieldCrash that reportedly reaches the same outcome through a condition the patch did not cover.

SYSTEM-level file reads on machines you already updated

ShieldCrash is assessed as a patch bypass for CVE-2026-69414 rather than a new, unrelated vulnerability. According to the researcher, Microsoft closed off several of the exploitation paths that ShieldBreak used but missed one specific condition, and that condition is reportedly still present on Windows 10, Windows 11 and Windows Server systems even after installing September’s updates. The proof of concept demonstrates arbitrary file reads with SYSTEM privileges. It does not currently grant write access, which is the only reason this has not already been rated as a full SYSTEM compromise.

Why “no write access” buys you very little

An attacker who can read any file on a machine as SYSTEM can pull credential material, configuration secrets, and private keys without ever touching disk in a way antivirus tooling is tuned to flag. Read-only primitives like this one are routinely the first stage of a longer chain, not the end of one, and defenders who wait for a write-capable exploit before treating this as urgent are giving that chain time to get built by someone else first. Microsoft has not published a fix, a workaround, or a revised timeline as of this writing.

What this means for your patch cadence

This is the second time in as many months that a Defender fix from Microsoft has been shown, by the same researcher, to leave the underlying issue reachable. If your organisation’s patch management treats a CVE as resolved the moment an update ships, without revisiting it when bypass research lands, ShieldCrash is exactly the kind of gap that approach will not catch, and the pattern suggests it will not be the last one from this research thread either.

If you want a European team to reassess how your endpoint fleet is exposed to ShieldCrash, or to build a vulnerability management process that catches bypass research instead of trusting the first patch, contact Excello Digital. We help organisations turn “patched” back into something they can actually verify.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!