Skip to finding
important · Privilege — Defender

ShieldCrash's released code does not establish its claimed post-fix SYSTEM file read.

Affects

Microsoft Defender Malware Protection Engine, the built-in antimalware engine on supported Windows clients and servers.

The repository combines Cloud Filter hydration, Object Manager links and an NTFS reparse point and claims arbitrary file read as SYSTEM with a path toward SYSTEM execution.

Detail and 4 sources

An independent reproduction reached the redirect pipeline, but SAM, SECURITY and ELAM reads failed before protected-file bytes were returned.

Chain to watch
Register a Cloud Filter synchronization root and seed a file for Defender remediation→↓Race Object Manager links and an NTFS reparse point during privileged handling→↓Attempt to substitute and return an attacker-selected protected file→↓The public code has not returned bytes from an attacker-selected protected file.
Unverified chainCorrect the sharing-violation and reparse timing failure, verify protected-file bytes on engine 1.1.26080.3, and only then test a controlled SYSTEM token transition.

The claimed post-fix capability remains unestablished until the code returns bytes from a protected target and demonstrates any resulting SYSTEM transition.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026