Article 789GN Serial Microsoft 0-day hunter drops yet another Defender exploit

Serial Microsoft 0-day hunter drops yet another Defender exploit

by
from www.theregister.com - Articles on (#789GN)
Story ImageZero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed ShieldCrash, which they claim will allow attackers to bypass the earlier ShieldBreak patch and read files as SYSTEM. I might rework this later into a full SYSTEM PoC but for now I'm dropping this skeleton PoC because I'm feeling a bit lazy," the prolific Microsoft bug hunter and thorn in Redmond's side said in their latest zero-day exploit's README. As is usual with Nightmare's zero-day cadence, they published ShieldCrash shortly after Microsoft released its latest Patch Tuesday security updates. According to Nightmare, this exploit works on Windows systems that have already applied the September patches. ShieldCrash purports to be a bypass of an earlier Defender privilege escalation zero-day, ShieldBreak (CVE-2026-69414), that allowed attackers to bypass another patch for another Nightmare Eclipse zero-day RoguePlanet (CVE-2026-50656). Redmond patched ShieldBreak last week, and RoguePlanet in July. Both allowed attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The latest bypass, ShieldCrash, allows arbitrary file reads as SYSTEM - but not arbitrary writes or a full SYSTEM shell, according to the researcher. Microsoft did not immediately respond to The Register's questions, including when it planned to patch ShieldCrash. We will update this story when we hear back. While the serial bug hunter typically finds and publishes Microsoft exploits - ShieldCrash is Nightmare's 11th Microsoft zero-day, and they have made clear that with Redmond, their vendetta is personal - they recently branched out into other security vendors' software. Last week, they released a zero-day bug called FalconFlank that affects CrowdStrike's Falcon endpoint security platform. This one still has a Windows twist: the privilege escalation bug abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. Security sleuth Kevin Beaumont confirmed the FalconFlank exploit works, along with several others Nightmare released over the past couple of weeks. These include HardBreacher, a now-patched elevation of privileges bug in Kaspersky's endpoint antivirus product, and PrettyPrague, an elevation of privileges vuln in Gen Digital's Avast antivirus software. (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments