Skip to content
Threat Feed
medium threat exploited

ShieldCrash Privilege Escalation in Microsoft Windows Defender

ShieldCrash is a privilege escalation vulnerability in Microsoft Windows Defender that exploits a race condition during the file remediation process by leveraging symbolic link manipulation.

ShieldCrash is a privilege escalation vulnerability targeting Microsoft Windows Defender. The attack exploits a race condition that occurs during the validation and remediation phases of file handling by the Windows Defender service (msmpeng.exe). By initiating a remediation action on a malicious file, an attacker can manipulate symbolic links to redirect the Windows Defender remediation process toward a staging directory under the attacker's control. This effectively subverts the security remediation logic, allowing for potential privilege escalation or arbitrary file operations within the context of the SYSTEM user. Defenders should monitor for the creation and rapid removal of specific intermediary artifacts generated by msmpeng.exe in non-standard locations, as these are diagnostic indicators of the exploit race condition.

Attack Chain

  1. Attacker prepares a malicious file or payload to trigger Windows Defender's detection engine.
  2. Attacker initiates a scan or triggers a remediation process for the target file.
  3. Attacker establishes a symbolic link (symlink) in a staging directory prior to the remediation step.
  4. Windows Defender validates the target file and proceeds to the remediation phase.
  5. Attacker swaps the symlink target while Defender is between the validation and deletion steps.
  6. Windows Defender follows the redirected path to the attacker-controlled staging area during the cleanup process.
  7. Windows Defender creates or modifies intermediary remediation artifacts within the attacker-controlled directory.
  8. Attacker observes the creation and subsequent removal of these artifacts as proof of exploitation success.

Impact

Successful exploitation allows local attackers to perform unauthorized file operations under the SYSTEM account, leading to privilege escalation on the affected Windows system. This technique has been identified as part of the broader 'RoguePlanet' threat campaign.

Recommendation

Deploy the provided Sigma rule to detect anomalous file activity associated with the Windows Defender service. Enable Sysmon Event IDs 11 (FileCreate), 15 (FileCreateStreamHash), and 23 (FileDelete) to capture the necessary telemetry for detecting the rapid creation and deletion of intermediary artifacts.


Immediate actions

Deploy Sigma rule to monitor for msmpeng.exe file activity in non-standard staging directories.

Detection Engineering 48h

Threat Hunt

Identify file create/delete events by msmpeng.exe outside of C:\Windows\Temp\

T1068 high high confidence hunt now

Data: Sysmon Event ID 11, 15, 23

Mitigations

Monitor vendor security bulletins for patches addressing the Windows Defender race condition.

medium_term IT Operations

Windows Defender

Detection coverage 1

Detect ShieldCrash Intermediary Defender Artifacts

high

Detects the creation and removal of intermediary remediation artifacts by Windows Defender indicative of ShieldCrash exploitation.

sigma tactics: privilege-escalation techniques: T1068 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →