Revised ShieldCrash PoC Bypasses Windows Defender to Read Protected Files

· Original article ↗

Summary

LevelBlue reports that a revised ShieldCrash PoC can let an unprivileged user read protected files, including the ELAM registry hive, by abusing Defender-related object-manager behavior. Researchers detail artifacts and detection signals.

Key points

  • The revised PoC, released September 15, successfully read files that the test user could not access, including a protected ELAM registry hive.
  • The earlier PoC was incomplete and returned ntdll.dll regardless of the requested target; LevelBlue validated the revised version in a fully patched VM.
  • ShieldCrash creates a mount point targeting \\BaseNamedObjects\\Restricted and a symbolic link from that namespace to a specified target file.
  • Tests observed staging directories under C:\\ and %TEMP%, and some runs left files or folders with broad permissions.
  • On an out-of-date Windows 11 system, MsMpEng.exe read the requested target; researchers did not observe this on fully updated test systems.
  • Defenders can monitor for the mount-point and symbolic-link sequence, unusual ShieldCrash-style staging directories, and related filesystem activity.
  • The article says the technique follows earlier Defender bypasses RoguePlanet and ShieldBreak, whose underlying mechanism persisted across two rounds of patching.

Article Details

Attack Vectors
  • ShieldCrash abuses an object-manager vulnerability by mapping a C:\ShieldCrash_<GUID> directory to \BaseNamedObjects\Restricted and creating a symbolic link from a BERN:stream path to a specified protected target, enabling unauthorized reads as an unprivileged user in the revised PoC.
  • The revised PoC was reported to successfully read protected files, including Secret.txt and the ELAM registry hive. The originally released PoC was incomplete and returned ntdll.dll instead of the requested target.
Defensive Notes
  • Monitor for ShieldCrash_<GUID>-style directories under C:\ or %TEMP%, especially when created by a non-SYSTEM process with Everyone: Full Control permissions.
  • Detect source mount points targeting \BaseNamedObjects\Restricted and symbolic links from that namespace to sensitive targets such as SAM or ELAM.
  • Monitor MsMpEng.exe for reads against paths supplied as PoC targets; the article observed this on an out-of-date Windows 11 asset, not fully updated test systems.
  • Correlate filesystem activity across C:\ and %TEMP% during a single session, and validate PoC output hashes: the original release returned ntdll.dll regardless of the requested file.
  • The article advises treating the September patch as incomplete and prioritizing behavioral detection of the object-manager mount-point and symlink sequence.

CVE

Vendors

Products

Tools

Related Articles