Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for Microsoft Defender ShieldCrash zero-day exploit granting SYSTEM privileges on fully patched Windows systems — no patch available

A security researcher has published a working proof-of-concept exploit called ShieldCrash that gives attackers SYSTEM-level access on fully patched Windows 10, Windows 11 and Windows Server machines — through Microsoft Defender itself. The exploit bypasses a fix Microsoft shipped just days ago in its record-breaking September Patch Tuesday update.

Why this one matters more than a typical zero-day

ShieldCrash is the third time in three months that the same researcher has bypassed Microsoft’s Defender patches — RoguePlanet in June, ShieldBreak in August, now ShieldCrash in September. For Australian SMBs relying on Defender as their primary endpoint protection (and most are — it ships with every Windows licence), the pattern matters more than any single flaw. The attack surface inside Defender itself is being systematically mapped, and each patch is being reverse-engineered within days.

The ASD’s Essential Eight framework lists patching applications within 48 hours of a critical update as a key control. But you can’t patch what hasn’t been fixed yet — and that’s exactly the situation right now.

What to do today

There is no official patch for ShieldCrash. In the meantime:

  • Verify your Defender definitions are current. They update automatically, but check — especially on machines that have been offline or sleeping.
  • Enable Attack Surface Reduction (ASR) rules if you haven’t already. These won’t block the exploit directly, but they limit what an attacker can do after gaining SYSTEM access.
  • Check whether your endpoint protection goes beyond Defender alone. A layered security stack — an EDR or managed detection and response service running alongside Defender — gives you visibility into the kind of privilege escalation activity ShieldCrash enables.

If you’re not sure whether your current setup would catch a privilege escalation exploit like this, talk to us. We run managed detection and response across our client base and can check your ASR rule configuration in minutes.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →