ShieldCrash Privilege Escalation in Microsoft Windows Defender
ShieldCrash is a privilege escalation vulnerability in Microsoft Windows Defender that exploits a race condition during the file remediation process by leveraging symbolic link manipulation.
ShieldCrash is a privilege escalation vulnerability targeting Microsoft Windows Defender. The attack exploits a race condition that occurs during the validation and remediation phases of file handling by the Windows Defender service (msmpeng.exe). By initiating a remediation action on a malicious file, an attacker can manipulate symbolic links to redirect the Windows Defender remediation process toward a staging directory under the attacker's control. This effectively subverts the security remediation logic, allowing for potential privilege escalation or arbitrary file operations within the context of the SYSTEM user. Defenders should monitor for the creation and rapid removal of specific intermediary artifacts generated by msmpeng.exe in non-standard locations, as these are diagnostic indicators of the exploit race condition.
Attack Chain
- Attacker prepares a malicious file or payload to trigger Windows Defender's detection engine.
- Attacker initiates a scan or triggers a remediation process for the target file.
- Attacker establishes a symbolic link (symlink) in a staging directory prior to the remediation step.
- Windows Defender validates the target file and proceeds to the remediation phase.
- Attacker swaps the symlink target while Defender is between the validation and deletion steps.
- Windows Defender follows the redirected path to the attacker-controlled staging area during the cleanup process.
- Windows Defender creates or modifies intermediary remediation artifacts within the attacker-controlled directory.
- Attacker observes the creation and subsequent removal of these artifacts as proof of exploitation success.
Impact
Successful exploitation allows local attackers to perform unauthorized file operations under the SYSTEM account, leading to privilege escalation on the affected Windows system. This technique has been identified as part of the broader 'RoguePlanet' threat campaign.
Recommendation
Deploy the provided Sigma rule to detect anomalous file activity associated with the Windows Defender service. Enable Sysmon Event IDs 11 (FileCreate), 15 (FileCreateStreamHash), and 23 (FileDelete) to capture the necessary telemetry for detecting the rapid creation and deletion of intermediary artifacts.
Immediate actions
Deploy Sigma rule to monitor for msmpeng.exe file activity in non-standard staging directories.
Threat Hunt
Identify file create/delete events by msmpeng.exe outside of C:\Windows\Temp\
Data: Sysmon Event ID 11, 15, 23
Mitigations
Monitor vendor security bulletins for patches addressing the Windows Defender race condition.
Windows Defender
Detection coverage 1
Detect ShieldCrash Intermediary Defender Artifacts
highDetects the creation and removal of intermediary remediation artifacts by Windows Defender indicative of ShieldCrash exploitation.
Detection queries are available on the platform. Get full rules →