Microsoft Defender ShieldBreak (CVE-2026-69414) patched Sep 2026; ShieldCrash incomplete-fix PoC
Microsoft Security Update Guide CVE-2026-69414 is an elevation of privilege in the Microsoft Malware Protection Engine (ShieldBreak): CVSS 3.1 base 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), Important. August reporting described a public local PoC to SYSTEM when Defender is enabled, including as a bypass of RoguePlanet (CVE-2026-50656). BleepingComputer (9 September 2026) says Microsoft shipped a ShieldBreak fix in the September 2026 Patch Tuesday set, and that researcher Nightmare Eclipse then released a "ShieldCrash" proof-of-concept claiming the patch is incomplete under specific conditions — arbitrary file read as SYSTEM on fully patched Windows 10/11/Server, without write access in the published skeleton PoC. Treat ShieldCrash as secondary researcher claim until MSRC documents a new CVE or revises 69414. Watch MSRC for engine build requirements; do not equate a public PoC with confirmed in-the-wild exploitation.
- Product
- Microsoft Malware Protection Engine (Microsoft Defender)
- Versions
- See MSRC / September 2026 Defender engine updates; ShieldCrash claims affect Sep-patched Windows 10/11/Server per researcher
- CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Exploited in Australia?
- unknown
- Patch to
- Apply September 2026 Defender/Malware Protection Engine updates; monitor MSRC for any ShieldCrash follow-up CVE
Primary: Microsoft Security Update Guide (CVE-2026-69414) · Vendor: CVE Record (Microsoft CNA) · CVE: CVE-2026-69414, CVE-2026-50656 · BleepingComputer (9 Sep 2026; ShieldCrash PoC after Sep patch)
