Revised ShieldCrash PoC Bypasses Windows Defender to Read Protected Files

Summary
LevelBlue reports that a revised ShieldCrash PoC can let an unprivileged user read protected files, including the ELAM registry hive, by abusing Defender-related object-manager behavior. Researchers detail artifacts and detection signals.
Key points
- The revised PoC, released September 15, successfully read files that the test user could not access, including a protected ELAM registry hive.
- The earlier PoC was incomplete and returned ntdll.dll regardless of the requested target; LevelBlue validated the revised version in a fully patched VM.
- ShieldCrash creates a mount point targeting \\BaseNamedObjects\\Restricted and a symbolic link from that namespace to a specified target file.
- Tests observed staging directories under C:\\ and %TEMP%, and some runs left files or folders with broad permissions.
- On an out-of-date Windows 11 system, MsMpEng.exe read the requested target; researchers did not observe this on fully updated test systems.
- Defenders can monitor for the mount-point and symbolic-link sequence, unusual ShieldCrash-style staging directories, and related filesystem activity.
- The article says the technique follows earlier Defender bypasses RoguePlanet and ShieldBreak, whose underlying mechanism persisted across two rounds of patching.
Article Details
- Attack Vectors
- ShieldCrash abuses an object-manager vulnerability by mapping a C:\ShieldCrash_<GUID> directory to \BaseNamedObjects\Restricted and creating a symbolic link from a BERN:stream path to a specified protected target, enabling unauthorized reads as an unprivileged user in the revised PoC.
- The revised PoC was reported to successfully read protected files, including Secret.txt and the ELAM registry hive. The originally released PoC was incomplete and returned ntdll.dll instead of the requested target.
- Defensive Notes
- Monitor for ShieldCrash_<GUID>-style directories under C:\ or %TEMP%, especially when created by a non-SYSTEM process with Everyone: Full Control permissions.
- Detect source mount points targeting \BaseNamedObjects\Restricted and symbolic links from that namespace to sensitive targets such as SAM or ELAM.
- Monitor MsMpEng.exe for reads against paths supplied as PoC targets; the article observed this on an out-of-date Windows 11 asset, not fully updated test systems.
- Correlate filesystem activity across C:\ and %TEMP% during a single session, and validate PoC output hashes: the original release returned ntdll.dll regardless of the requested file.
- The article advises treating the September patch as incomplete and prioritizing behavioral detection of the object-manager mount-point and symlink sequence.
CVE
Vendors
CrowdStrikeIn our previous blog, we analyzed four proofs of concept (PoCs) from the leak persona Nightmare-Eclipse that targeted Kaspersky, Avast, NVIDIA, and CrowdStrike, respectively.MicrosoftImmediately following Microsoft's September 2026 Patch Tuesday, the actor released ShieldCrash, a Windows Defender privilege-escalation bypass — and the third entry in a lineage we've been tracking since our coverage ofSentinelOneSentinelOne captured file system activity tied to the ShieldCrash_{GUID} directories in both C:\ and %TEMP%.
Products
Windows 11We tested the released PoC across several fully patched Windows 11 and Windows Server builds, plus one deliberately out-of-date Windows 11 asset.Windows DefenderHow does Nightmare-Eclipse bypass successive Windows Defender patches to execute arbitrary file reads using ShieldCrash?Windows ServerWe tested the released PoC across several fully patched Windows 11 and Windows Server builds, plus one deliberately out-of-date Windows 11 asset.
Tools
Process MonitorProcess Monitor captured several events in which MsMpEng.exe (Defender's own engine process) performed a read operation directly against the ELAM target file in question.ShieldCrashHow does Nightmare-Eclipse bypass successive Windows Defender patches to execute arbitrary file reads using ShieldCrash?