Security News New Windows Defender zero-day blocks Microsoft antivirus updates

Security News
4 Replies 415 Views

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.

Naceri named it BigDiskBuster and said it is similar to another Defender zero-day known as UnDefend, which he released in April and that allowed standard users to block definition updates.

The security researcher added that BigDiskBuster works on all supported Windows versions and that it needs to run in the background to block Defender updates.

"Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background," he said.

"This proof of concept is similar to UnDefend, it prevents windows defender from performing platform/signature updates. Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea."
Since April 2026, Naceri, who claims to be a former Microsoft employee, has released almost a dozen zero-day exploits as part of an ongoing dispute with Microsoft over their alleged unfair termination in March 2025.

Naceri also released several zero-day exploits that allowed privilege escalation on various Windows versions five years ago.

Two weeks ago, they released another Defender zero-day exploit that grants SYSTEM access (known as 'ShieldCrash') right after Microsoft rolled out this month's Patch Tuesday security updates.

According to Naceri, ShieldCrash bypasses another ShieldBreak Defender privilege escalation flaw patched a week earlier, which itself bypassed RoguePlanet, another Defender flaw the security researcher disclosed in June and Microsoft patched in July.

Naceri's zero-day exploits released this year also include LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, which target Microsoft Defender, BitLocker, and other Windows components.

Microsoft initially responded with warnings of legal action against anyone engaging in "malicious activity causing real harm" to the company's customers, leading many in the infosec community to believe that Microsoft was directly threatening the security researcher.

While Microsoft has fixed some of the security flaws Naceri disclosed (such as ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws), the other security issues still lack an official patch.

A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out about the BigDiskBuster denial-of-service zero-day.
 
Hi, this is worth watching, but the quoted report does not describe a remote attack that spontaneously disables Defender. BigDiskBuster reportedly has to be running on the machine to keep Defender updates blocked, so an attacker would first need some way to execute it.

What the report actually establishes​

The reported effect is a denial of Defender platform and security-intelligence updates while the proof of concept remains active. That matters because protection can gradually fall behind, but it is not the same as disabling every Defender protection feature or proving that a PC has been compromised.

Several details in the quote—including operation on every supported Windows version and the standard-user implications inherited from the comparison with UnDefend—are attributed to the researcher. No independent reproduction or Microsoft advisory is supplied here. The current status of a Microsoft fix specifically for BigDiskBuster is also not confirmed.

Practical response​

There is no reason to disable Defender or install the proof of concept to test it. Keep Windows updated and obtain software only from trusted sources—the exploit still needs execution.

Administrators should monitor whether Defender updates continue succeeding rather than relying only on the tray icon. Useful checks include:

  1. Open Windows Security → Virus & threat protection → Protection updates and check that the security-intelligence version and update time continue advancing.
  2. In managed environments, alert on repeated Defender platform or intelligence-update failures and unexpectedly stale endpoints.
  3. Investigate a machine if updates remain stale despite connectivity and normal update services; this report is only one possible explanation, not a diagnosis.
  4. If the proof of concept or another suspicious program was actually executed, isolate the device as appropriate and seek individualized analysis through MalwareTips’ Malware Removal Assistance team. A manual update apparently succeeding once would not settle the matter if the suspected process is still active.

For ordinary users whose Defender updates are current and who have not run untrusted code, the report alone does not call for emergency remediation. The sensible move is verification, not panic—or feeding a buggy zero-day proof of concept to the family PC in the name of science.
 
Community
Security tip
Test a small restore. Restore a few files from your backup to a separate folder and open them. A successful backup notification is more useful when you have checked recovery yourself.
Back
Top