Microsoft Defender update-blocking disk exhaustion security flaw
Vulnerability
Summary
Hide ▲
Show ▼
BigDiskBuster exposes a Microsoft Defender flaw that can block platform and signature updates by exhausting disk space, leaving detection content stale on affected Windows systems. The zero-day proof-of-concept was published on GitHub on September 19, and there is no patch, CVE, or Microsoft advisory yet. The tool also targets MRT.exe, and the reported behavior appears to affect supported Windows versions.
Related Happenings
Microsoft Defender update-blocking zero-day security flaw
Vulnerability
H score7
First: 22.09.2026 12:55
Last: 22.09.2026 12:55
Sources 1
About this happening:
A Microsoft Defender zero-day named BigDiskBuster can block platform/signature updates on supported Windows versions, freezing antivirus updates while it runs in t...
Microsoft Defender update-blocking zero-day security flaw
VulnerabilityAbout this happening: A Microsoft Defender zero-day named BigDiskBuster can block platform/signature updates on supported Windows versions, freezing antivirus updates while it runs in t...
Microsoft Defender Antivirus false 'turned off' alerts after latest updates
Security Tool/Service
H score11
First: 31.08.2026 11:29
Last: 31.08.2026 11:29
Sources 1
About this happening:
Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though p...
Microsoft Defender Antivirus false 'turned off' alerts after latest updates
Security Tool/ServiceAbout this happening: Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though p...
Latest development: 18.09.2026 15:16
Microsoft fixed the Defender Antivirus false-status alert issue in Microsoft Defender Antivirus update version 4.18.26080.4, released on September 17. The update addresses erroneous Windows Security app notifications that said "Microsoft Defender Antivirus is turned off" even though protection remained active, across supported Windows client and server versions including Windows 11 26H1 and Windows Server 2025.
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/Service
H score11
First: 19.08.2026 14:14
Last: 19.08.2026 14:14
Sources 1
About this happening:
Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/ServiceAbout this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation Wave
H score41
First: 30.06.2026 11:53
Last: 30.06.2026 11:53
Sources 1
About this happening:
CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation WaveAbout this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
Vulnerability
H score32
First: 17.06.2026 11:32
Last: 17.06.2026 11:32
Sources 1
About this happening:
Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
VulnerabilityAbout this happening: Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
Timeline
-
22.09.2026 19:14 2 articles · 2h ago
BigDiskBuster proof-of-concept appears on GitHub
Initial DisclosureBigDiskBuster, a zero-day proof-of-concept attributed to Abdelhamid Naceri, watches Defender update paths on C:\\ and creates a hidden temporary file sized to fill all remaining free space when Microsoft Defender begins downloading a platform or definition update, causing the update to fail while Defender continues running; the tool also opens a handle on MRT.exe, the Windows Malicious Software Removal Tool.
Show sources
- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates — thehackernews.com — 22.09.2026 19:14
- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates — thehackernews.com — 22.09.2026 19:14
-
22.09.2026 19:14 1 articles · 2h ago
BigDiskBuster leaves Microsoft Defender detection content stale
Victim Impact UpdateThe disk-filling technique can leave Microsoft Defender's detection content stale, and the report says no patch or vendor workaround exists for BigDiskBuster. Naceri says the tool is similar to UnDefend, a Defender denial-of-service flaw disclosed in April and patched by Microsoft in May as CVE-2026-45498 in Antimalware Platform version 4.18.26040.7, but the article says it is not established that the May fix covers the new method; administrators are advised to check Defender versions, monitor repeated update failures, sustained low disk space, and hidden files, and restrict unknown binaries with WDAC or AppLocker.
Show sources
- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates — thehackernews.com — 22.09.2026 19:14