A security researcher has released proof-of-concept code for a new Microsoft Defender vulnerability that can prevent the antivirus platform from installing security-intelligence and platform updates across supported versions of Windows.
The newly disclosed technique, named BigDiskBuster , targets the process Microsoft Defender Antivirus uses to stage and install updates. If successfully deployed, it can keep the security product running while quietly preventing it from receiving the latest malware signatures, detection logic, scanning-engine components and platform improvements.
The issue was disclosed by security researcher Abdelhamid Naceri , who also uses the online name Nightmare Eclipse . Naceri published the BigDiskBuster source code over the weekend and described the issue as a denial-of-service vulnerability affecting Defender’s update mechanism.
According to the researcher, the proof of concept works on all currently supported Windows versions, although the publicly released implementation remains experimental and must continue running in the background to interfere with updates.
At the time of publication, Microsoft had not publicly confirmed the vulnerability, assigned it a CVE identifier or released a security update specifically addressing BigDiskBuster. There was also no verified evidence that attackers were exploiting the technique in real-world intrusions.
That distinction is important. BigDiskBuster is currently a publicly available proof of concept rather than a confirmed, actively exploited zero-day campaign. Nevertheless, the release of working source code gives threat actors an opportunity to study, modify and potentially incorporate the technique into malware.
Defender remains active but gradually loses protection
BigDiskBuster does not appear to disable Microsoft Defender Antivirus outright. Instead, it attacks one of the security product’s most important dependencies: its ability to stay current.
Modern antivirus protection is not a static capability installed once with Windows. Defender receives several different categories of updates, each serving a separate security function.
Security-intelligence updates contain the signatures, indicators and detection logic used to identify emerging malware. Microsoft normally delivers these updates multiple times per day. Engine updates modify the underlying scanning technology, while platform updates replace or improve Defender’s executable files, libraries, drivers and service components.
Microsoft’s documentation states that keeping Defender current is critical for protecting devices against new malware and attack techniques. Security-intelligence updates are distributed under KB2267602, while monthly platform updates are delivered under KB4052623.
A computer affected by BigDiskBuster may therefore continue to report that Defender is installed and running, while its knowledge of the threat landscape becomes increasingly outdated.
That creates a potentially deceptive security condition. Users may see the familiar Defender interface, active real-time protection and apparently healthy Windows Security status indicators without immediately realising that the underlying signatures or platform components have stopped advancing.
The longer that condition continues, the larger the detection gap may become. Newly released ransomware, information stealers, loaders and other rapidly changing malware families are frequently modified specifically to evade existing signatures. Cloud-delivered protection and behavioural analysis can provide additional layers of defence, but they do not make local security-intelligence and platform updates unnecessary.
Proof of concept manipulates available disk space
An examination of the publicly released BigDiskBuster repository indicates that the technique watches directories used by Microsoft Defender to stage platform and definition updates.
When the program detects activity associated with a Defender update, it creates hidden temporary files and allocates the available storage space to them. This produces an artificial disk-full condition at the critical point in the update process.
The approach does not merely fill the disk once and stop. The proof-of-concept code monitors filesystem activity, reacts to Defender update directories and attempts to reclaim newly available space as files are modified or removed. When it detects that the Defender update has failed, it releases the allocated storage and removes its temporary files.
In practical terms, the program briefly deprives Defender’s updater of the free space it needs to stage or install new files. Once the update operation collapses, the proof of concept frees the storage, reducing the likelihood that a user will notice a permanently full system drive.
This helps explain the BigDiskBuster name: rather than directly modifying Defender’s protected files or attempting to stop its services, the technique weaponises disk allocation to disrupt a trusted security operation.
The published code specifically monitors paths associated with Defender’s Platform and Definition Updates directories. It then repeats the disk-allocation process when it detects relevant file creation or size changes.
Because the technique interferes with the update process indirectly, it may be more difficult for ordinary users to distinguish malicious interference from a routine update failure, storage problem or Windows Update error.
Local execution is required
BigDiskBuster should not be confused with a vulnerability that an unauthenticated attacker can exploit remotely over the internet.
An attacker would first need to execute the proof of concept—or malware incorporating the same technique—on the targeted Windows device. The technique is therefore most relevant as a post-compromise capability.
For example, an attacker who gains initial access through phishing, a malicious download, stolen credentials, an exposed remote-management service or another software vulnerability could deploy an update-blocking component before installing additional malware.
That sequence could allow the attacker to freeze Defender’s protection at a known point in time and then introduce payloads engineered to evade the older detection set.
The vulnerability’s value to an attacker is therefore not necessarily as the first stage of an intrusion. Its more likely role would be defence evasion or persistence support: maintaining a widening gap between the endpoint’s security intelligence and the current threat environment.
Security teams should also distinguish between exploit prerequisites and impact. Requiring prior code execution reduces the likelihood of mass exploitation directly from the internet, but it does not make the issue insignificant. Many enterprise attacks begin with user-level access and then use separate techniques to weaken endpoint controls.
A successor to the earlier UnDefend disclosure
Naceri said BigDiskBuster is similar in objective to UnDefend , another Defender update-blocking technique disclosed in April 2026.
UnDefend reportedly allowed a standard Windows user to interfere with Defender definition updates. Microsoft subsequently referenced UnDefend in a statement covering a series of vulnerabilities that had been publicly released without prior coordination with the company.
BigDiskBuster uses a different operational concept but aims for the same strategic result: preventing Defender from receiving the updates required to recognise and respond to newly emerging threats.
The release forms part of a much larger and increasingly contentious series of Windows and Defender vulnerability disclosures associated with Nightmare Eclipse.
Since April, the researcher has published or described nearly a dozen issues carrying names including BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, UnDefend, RoguePlanet, ShieldBreak, ShieldCrash and LegacyHive.
These disclosures have affected multiple Windows security components, including Microsoft Defender Antivirus and BitLocker. Some have enabled local privilege escalation or SYSTEM-level code execution, while others have targeted update mechanisms or other defensive functions.
Microsoft has fixed several of the reported vulnerabilities, but others have remained unresolved or have not yet received public CVE identifiers.
Defender vulnerabilities have triggered repeated patch-and-bypass cycles
Several of the earlier vulnerabilities illustrate the speed at which the dispute has evolved.
RoguePlanet, tracked as CVE-2026-50656 , was a race-condition vulnerability in the Microsoft Malware Protection Engine. The publicly released exploit reportedly allowed an attacker with local access to obtain SYSTEM privileges on fully patched Windows 10 and Windows 11 computers.
Microsoft addressed RoguePlanet in July by releasing Malware Protection Engine version 1.1.26060.3008.
A later vulnerability named ShieldBreak was subsequently patched, but Naceri claimed that another exploit, ShieldCrash, could bypass the protection Microsoft introduced. BigDiskBuster now adds a separate update-denial technique to that chain of disclosures.
This repeated cycle is particularly concerning for endpoint security products. Defender is designed to inspect potentially hostile files, scripts, archives, documents and memory activity. That privileged position makes it a powerful defensive tool, but it also creates a valuable attack surface.
A vulnerability in an ordinary application may compromise that application. A weakness in endpoint security software can potentially give an attacker a way to evade, disable or even abuse the system intended to detect the intrusion.
Microsoft and the researcher remain in dispute
The disclosures are unfolding against an acrimonious dispute between Naceri and Microsoft.
Naceri claims to be a former Microsoft employee and has linked the release of the vulnerabilities to what he describes as unfair treatment and termination by the company. Microsoft has not publicly substantiated those claims.
In May, Microsoft published a statement criticising the release of multiple zero-day vulnerabilities without advance coordination. The company said the details had not been provided to Microsoft before publication, limiting its ability to investigate and protect customers before proof-of-concept code became publicly accessible.
Microsoft specifically named RedSun, UnDefend, BlueHammer and YellowKey among the uncoordinated disclosures. It said its security teams were working to understand the issues and develop updates, while warning that public exploit releases could expose customers to unnecessary risk.
The company also said its Digital Crimes Unit would continue pursuing cases against actors involved in malicious activity that caused real harm to customers.
Microsoft nevertheless reiterated that researchers could submit vulnerabilities through its public reporting portal regardless of their identity, reputation or interactions with the company.
The disagreement highlights the persistent tension surrounding vulnerability disclosure. Researchers may resort to public release when they believe a vendor has ignored, undervalued or mishandled a report. Vendors argue that publishing exploit code before a patch is ready creates immediate opportunities for criminal groups and hostile state actors.
For customers, however, the motivations behind a disclosure do not change the operational risk. Once functioning proof-of-concept code becomes publicly available, defenders must assume that both researchers and adversaries can analyse it.
Why blocked security updates matter
Microsoft Defender receives security-intelligence updates several times per day. Platform and engine updates are generally released on a monthly schedule, with administrators able to control deployment channels and update sources.
Enterprises can obtain protection updates through Microsoft Update, Windows Server Update Services, Microsoft Configuration Manager, a software update point or an internal file . Microsoft also supports fallback orders so endpoints can switch to another source if their preferred update service is unavailable.
BigDiskBuster appears to interfere at the local staging and installation level. If that assessment is correct, simply configuring additional download sources may not fully address the problem. An endpoint could successfully download an update from Microsoft Update, WSUS or another approved source but still fail when attempting to write or install the package locally.
That makes update-age monitoring more important than checking only whether an endpoint can an update server.
Security operations teams should track the actual security-intelligence version and the time at which it was last updated. Microsoft provides the Get-MpComputerStatus PowerShell command for viewing Defender status, including antivirus-signature information.
Enterprises using Microsoft Defender for Endpoint or another endpoint-management platform should look for groups of systems that stop receiving updates at the same time, repeatedly fail installation or remain on versions older than the organisation’s normal threshold.
What administrators should do now
Until Microsoft confirms the issue and provides formal guidance, organisations should treat BigDiskBuster primarily as a local defence-evasion risk.
Administrators should monitor endpoints for unexpectedly stale Defender security intelligence, repeated update failures and unexplained changes in available disk space. A system that briefly loses nearly all free storage during a Defender update and then recovers it warrants investigation.
Teams should also look for unknown processes monitoring or interacting with Defender’s directories under ProgramData, particularly when those processes create large hidden files or rapidly allocate and release disk space.
Defender update failures should not automatically be attributed to BigDiskBuster. Microsoft documents many legitimate reasons that updates can fail, including network problems, incorrect WSUS configuration, conflicts with other security products and Windows Update errors. Microsoft’s troubleshooting guidance recommends collecting update-source, error-code and event information to identify the stage at which an update failed.
However, repeated failures accompanied by suspicious local processes, unusual filesystem activity or unexplained storage exhaustion should be escalated as a potential security incident.
Organisations should consider the following defensive actions:
Continuously compare each endpoint’s Defender signature, engine and platform versions with the versions approved or expected by the organisation. Alert when security intelligence has not updated within the normal operational window, rather than relying solely on whether Defender reports itself as enabled. Investigate repeated Defender update failures, especially when multiple update sources produce the same result. Monitor for rapid allocation of large hidden or temporary files and abrupt changes in system-drive free space. Use application control to prevent unknown or unapproved executables from running, particularly from user-writable directories. Maintain layered endpoint protection so that one compromised security component does not become the organisation’s only source of detection. Preserve Defender operational logs, Windows Update logs and endpoint telemetry when suspicious failures occur. Test Microsoft’s eventual fix in a controlled deployment ring before broad rollout, while prioritising rapid installation once compatibility has been confirmed.
Continuously compare each endpoint’s Defender signature, engine and platform versions with the versions approved or expected by the organisation.
Alert when security intelligence has not updated within the normal operational window, rather than relying solely on whether Defender reports itself as enabled.
Investigate repeated Defender update failures, especially when multiple update sources produce the same result.
Monitor for rapid allocation of large hidden or temporary files and abrupt changes in system-drive free space.
Use application control to prevent unknown or unapproved executables from running, particularly from user-writable directories.
Maintain layered endpoint protection so that one compromised security component does not become the organisation’s only source of detection.
Preserve Defender operational logs, Windows Update logs and endpoint telemetry when suspicious failures occur.
Test Microsoft’s eventual fix in a controlled deployment ring before broad rollout, while prioritising rapid installation once compatibility has been confirmed.
No confirmed exploitation so far
The public release of BigDiskBuster increases risk, but it does not by itself demonstrate that the vulnerability is being used in attacks.
As of September 22, Microsoft had not published a dedicated advisory for BigDiskBuster, assigned it a CVE number or confirmed exploitation. No authoritative source had linked the technique to ransomware, state- operations or other active campaigns.
Claims that the vulnerability affects every supported Windows version currently originate from the researcher and have not yet been independently confirmed by Microsoft.
For that reason, organisations should avoid overstating the threat while still responding to the exposure. The most accurate description is that working proof-of-concept code is publicly available for a claimed Defender update-denial vulnerability, and the vendor has not yet released a specific fix or full technical assessment.
BigDiskBuster nevertheless exposes a broader security problem: antivirus protection is only as current as its latest successful update. An endpoint that appears protected but can no longer refresh its detection intelligence may become progressively easier to compromise without producing an obvious warning.
Until Microsoft issues an official response, defenders should closely monitor update freshness, investigate anomalous storage behaviour and treat unexplained Defender update failures as a possible sign of deliberate interference rather than routine maintenance trouble.
Cyber Security Hub
To view or add a , sign in
More articles by The Cyber Security Hub™
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
