New Windows Defender Exploit Blocks Critical Antivirus Updates
Share
Security researcher Abdelhamid Naceri, known online as Nightmare Eclipse, has disclosed a new zero-day exploit named BigDiskBuster that prevents Microsoft Defender from performing critical antivirus updates.
The flaw allows a tool running in the background to block both platform and signature updates. If successful, the antivirus software remains stuck on its current version, potentially leaving the system vulnerable to new threats that require updated definitions to detect.
Impact across Windows versions
Naceri stated that BigDiskBuster appears to work across all supported versions of Windows. While the proof-of-concept (PoC) is reportedly somewhat unstable and requires further refinement, the core mechanism effectively denies the antivirus software its ability to refresh its security database.
The exploit is similar in function to UnDefend, another zero-day released by the researcher in April 2026, which similarly allowed users to block definition updates.
Ongoing dispute with Microsoft
The disclosure is part of a series of vulnerabilities identified by Naceri following an alleged unfair termination from Microsoft in March 2025. Since April 2026, the researcher has released nearly a dozen exploits targeting various Windows components, including BitLocker and Microsoft Defender.
Previous disclosures include ShieldCrash, which grants SYSTEM-level access, as well as flaws such as LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, and MiniPlasma. While Microsoft has issued patches for some of these vulnerabilities—including ShieldBreak and RoguePlanet—others remain unpatched at the time of reporting.
Microsoft has previously warned that it would take legal action against individuals engaging in malicious activity that causes real harm to its customers. The company has not yet provided an official comment regarding the BigDiskBuster denial-of-service exploit.




Leave a Reply