“The latest bypass, ShieldCrash, allows arbitrary file reads as SYSTEM - but not arbitrary writes”

ShieldCrash bypasses the patch Microsoft shipped for ShieldBreak, and it reads any file on a fully updated machine as SYSTEM. That is the security product doing it. This is the same researcher’s eleventh Microsoft zero-day, which says the patches keep addressing the specific proof-of-concept instead of the underlying design. Enterprises pay extra for Defender.