CVE-2026-69414
Microsoft Defender Elevation of Privilege Vulnerability
- Published
- Aug 14, 2026
- Updated
- Sep 16, 2026
- Assigning CNA
- microsoft
- Evidence observed
- Aug 18, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 45.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
Sources
3- ShieldCrashPoC
Proof-of-concept exploit for CVE-2026-69414, a Windows Defender 0day enabling arbitrary file read as SYSTEM on all supported Windows versions.
- ShieldBreakPoC
Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint protection.
Educational lab and proof-of-concept materials for a specific CVE, providing sandboxed scripts and templates for vulnerability research, authorized testing, and defensive security training.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.