{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/shieldcrash/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows Defender"],"_cs_severities":["medium"],"_cs_tags":["windows-defender","privilege-escalation","shieldcrash","rogueplanet"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eShieldCrash is a privilege escalation vulnerability targeting Microsoft Windows Defender. The attack exploits a race condition that occurs during the validation and remediation phases of file handling by the Windows Defender service (msmpeng.exe). By initiating a remediation action on a malicious file, an attacker can manipulate symbolic links to redirect the Windows Defender remediation process toward a staging directory under the attacker's control. This effectively subverts the security remediation logic, allowing for potential privilege escalation or arbitrary file operations within the context of the SYSTEM user. Defenders should monitor for the creation and rapid removal of specific intermediary artifacts generated by msmpeng.exe in non-standard locations, as these are diagnostic indicators of the exploit race condition.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker prepares a malicious file or payload to trigger Windows Defender's detection engine.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a scan or triggers a remediation process for the target file.\u003c/li\u003e\n\u003cli\u003eAttacker establishes a symbolic link (symlink) in a staging directory prior to the remediation step.\u003c/li\u003e\n\u003cli\u003eWindows Defender validates the target file and proceeds to the remediation phase.\u003c/li\u003e\n\u003cli\u003eAttacker swaps the symlink target while Defender is between the validation and deletion steps.\u003c/li\u003e\n\u003cli\u003eWindows Defender follows the redirected path to the attacker-controlled staging area during the cleanup process.\u003c/li\u003e\n\u003cli\u003eWindows Defender creates or modifies intermediary remediation artifacts within the attacker-controlled directory.\u003c/li\u003e\n\u003cli\u003eAttacker observes the creation and subsequent removal of these artifacts as proof of exploitation success.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows local attackers to perform unauthorized file operations under the SYSTEM account, leading to privilege escalation on the affected Windows system. This technique has been identified as part of the broader 'RoguePlanet' threat campaign.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to detect anomalous file activity associated with the Windows Defender service. Enable Sysmon Event IDs 11 (FileCreate), 15 (FileCreateStreamHash), and 23 (FileDelete) to capture the necessary telemetry for detecting the rapid creation and deletion of intermediary artifacts.\u003c/p\u003e\n","date_modified":"2026-10-01T20:06:09Z","date_published":"2026-10-01T20:06:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-shieldcrash/","summary":"ShieldCrash is a privilege escalation vulnerability in Microsoft Windows Defender that exploits a race condition during the file remediation process by leveraging symbolic link manipulation.","title":"ShieldCrash Privilege Escalation in Microsoft Windows Defender","url":"https://feed.craftedsignal.io/briefs/2026-10-shieldcrash/"}],"language":"en","title":"CraftedSignal Threat Feed - Shieldcrash","version":"https://jsonfeed.org/version/1.1"}