Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit

Published September 10, 2026

A researcher released a new zero-day exploit that can crash Windows Defender on Windows PCs. Attackers could use this to stop the security software from running, leaving your system unprotected.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Affects
Windows
Exploited
Not confirmedNo confirmation recorded

How it works

  • The researcher found a flaw in Windows Defender that lets attackers send a specially crafted file or request to the Defender service.
  • When Windows tries to analyze this file, it crashes instead of running normally.
  • This crash stops Defender from protecting your PC until you restart it.

What to do

If you use Windows Defender on your PC and have not yet installed the latest Windows updates, you are affected. Check your Windows version by typing 'winver' in the search bar and pressing Enter. Find the installed Windows version and consult the vendor advisory. The supplied source does not give a reliable affected-version cutoff.

As a temporary fix, disable file and email scanning in Windows Defender until Microsoft releases an update. To do this, go to Windows Security settings, then adjust the scanning options. For now, avoid opening suspicious files or links.

Technical details

The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.