Threat Intelligence

Microsoft Defender's ShieldBreak Fix Bypassed: New PoC Shows Flaw Still Exploitable

The Hacker News · 9 Sept 2026
Key Takeaway Ensure Microsoft Defender and other security software are set to update automatically, and monitor vendor advisories closely as this bypass has not yet been fully resolved.

Security researcher Chaotic Eclipse has published a proof-of-concept exploit for a new issue dubbed ShieldCrash, which bypasses Microsoft's recent patch for CVE-2026-69414 (also known as ShieldBreak). According to the researcher, Microsoft's fix closed several avenues for exploitation but missed one, meaning the original vulnerability can still be triggered under specific conditions. The PoC demonstrates an arbitrary file read at SYSTEM level on the latest version of Windows, with all supported versions reportedly affected.

The original ShieldBreak flaw, rated 7.8 on the CVSS scale, was patched days earlier through an update to the Microsoft Malware Protection Engine (version 1.1.26080.3). Microsoft has stated the fix requires no customer action and only applies to systems with Defender enabled, noting that its antimalware products are configured by default to update automatically.

This is part of a broader pattern from Chaotic Eclipse, who has recently disclosed similar proof-of-concept exploits affecting CrowdStrike Falcon Sensor, Kaspersky, Avast Antivirus, and NVIDIA products. Kaspersky and Avast have already issued patches, while CrowdStrike says it is investigating the report.

Microsoft Defender vulnerability proof-of-concept patch bypass endpoint security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.