Defender zero-day halts antivirus updates
A researcher's new Windows Defender zero-day prevents signature and platform updates, the latest in a string of exploits tied to a dispute with Microsoft.
A security researcher has released another zero-day exploit targeting Microsoft Defender, this one designed to stop the antivirus from updating itself. The tool, called BigDiskBuster, was published over the weekend by Abdelhamid Naceri, who goes by the handle Nightmare Eclipse. According to Naceri, it works on all supported Windows versions and must run in the background to be effective.
The exploit is the latest in a series of zero-days Naceri has disclosed since April 2026 as part of an ongoing dispute with Microsoft over what the researcher describes as an unfair termination in March 2025. The company has patched some of the flaws but not others, and a Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out about the BigDiskBuster denial-of-service zero-day.
What BigDiskBuster does
BigDiskBuster blocks Windows Defender from performing updates, leaving the antivirus stuck at its current version as long as the tool is running. Naceri described the exploit as similar to UnDefend, an earlier Defender zero-day he released in April that allowed standard users to block definition updates.
The researcher said BigDiskBuster needs to run continuously in the background to prevent updates. In a message accompanying the release, Naceri explained that the tool completely denies Defender from updating, so users are stuck with their current version if the tool is active.
"Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background," he said.
He added that the proof-of-concept is similar to UnDefend and prevents Windows Defender from performing platform and signature updates. Naceri noted that it seems to work on all supported Windows versions, though the proof-of-concept is a bit buggy and needs some rewriting, but the idea is clear.
Part of a larger pattern
Since April 2026, Naceri has released almost a dozen zero-day exploits as part of his dispute with Microsoft. Two weeks ago, he released another Defender zero-day that grants SYSTEM access, known as 'ShieldCrash', right after Microsoft rolled out this month's Patch Tuesday security updates.
According to Naceri, ShieldCrash bypasses another Defender privilege escalation flaw called ShieldBreak, which was patched a week earlier. ShieldBreak itself bypassed RoguePlanet, another Defender flaw the researcher disclosed in June and Microsoft patched in July.
The exploits Naceri has released this year also include LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, which target Microsoft Defender, BitLocker, and other Windows components.
Microsoft's response and remaining gaps
Microsoft initially responded to Naceri's disclosures with warnings of legal action against anyone engaging in "malicious activity causing real harm" to the company's customers, leading many in the infosec community to believe that Microsoft was directly threatening the security researcher.
While Microsoft has fixed some of the security flaws Naceri disclosed, such as ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, the other security issues still lack an official patch. The company has not commented publicly on BigDiskBuster.
The BigDiskBuster exploit is a denial-of-service tool, meaning it does not grant elevated privileges or remote code execution. Its impact is limited to preventing Defender from updating, which could leave systems exposed to newer threats if the tool is deployed. However, the tool must be running in the background to have an effect, and it is currently a proof-of-concept with acknowledged bugs.
Technical mechanics of update blocking
Windows Defender relies on regular updates to its platform and signature databases to detect new malware. Blocking these updates means the antivirus engine remains at an older version, potentially missing detections for recently discovered threats. BigDiskBuster appears to interfere with the update process, though the exact mechanism has not been detailed by Naceri.
UnDefend, the earlier tool, allowed standard users to block definition updates, which suggests the new exploit may exploit a similar weakness in how Defender handles update requests. Naceri's description indicates that BigDiskBuster works across all supported Windows versions, making it broadly applicable.
The proof-of-concept's buggy nature means it may not work reliably in all environments, but the underlying technique could be refined by others. The fact that it requires background execution means an attacker would need ongoing access to a system to maintain the block.
Who is affected and how
Any Windows system running Microsoft Defender could potentially be affected if an attacker can execute the BigDiskBuster tool with the necessary privileges. Since the tool blocks updates, the primary risk is that a system remains unprotected against new threats that require updated signatures or platform improvements.
For enterprises, this could undermine endpoint security if the tool is used as part of a broader attack. However, the tool itself does not provide a pathway to compromise a system; it is a denial-of-service mechanism that degrades Defender's effectiveness. Standard users may be able to run it, similar to UnDefend, which would lower the bar for exploitation.
Microsoft has not released a patch for BigDiskBuster, and it is unclear whether the company plans to address it. The researcher's history suggests that more zero-days may be forthcoming if the dispute continues.
The dispute with Microsoft
Naceri's disclosures are tied to a dispute with Microsoft that began after what he describes as an unfair termination in March 2025. Since then, he has published multiple zero-day exploits targeting Microsoft products, often releasing them shortly after Patch Tuesday updates.
Microsoft's initial response included warnings of legal action, which some in the security community interpreted as a threat against the researcher. The company has since patched several of the disclosed flaws, but others remain unaddressed. The dynamic highlights tensions between security researchers and vendors when disclosure timelines and employment disputes intersect.
Naceri has not indicated whether he will continue releasing exploits, but the pattern suggests that more may come. The BigDiskBuster release is the latest in a series that has kept Microsoft's security teams busy.
What defenders can do
For now, there is no official patch for BigDiskBuster. Organizations should ensure that Defender updates are functioning properly and monitor for unauthorized tools that might interfere with antivirus operations. Since the tool requires background execution, endpoint detection and response systems could potentially flag its presence.
Security teams may also want to review their defenses against denial-of-service attacks that target security software. While BigDiskBuster itself is a proof-of-concept, the technique could be adopted by other actors. Maintaining multiple layers of security, including network-based detection and regular system audits, can help mitigate the risk of a degraded antivirus engine.
Microsoft has not provided guidance specific to this zero-day. The company's standard advice for keeping systems protected includes enabling automatic updates and using additional security tools. However, if Defender updates are blocked, those measures may be insufficient.
Why it matters
The release of BigDiskBuster underscores the challenges vendors face when a disgruntled researcher turns to public disclosure. For businesses and consumers, it means that even built-in security tools can be undermined by a determined attacker with access to a system. The lack of a patch leaves a window of exposure, however narrow, that could be exploited by others.
This incident also raises questions about the sustainability of bug bounty and disclosure programs when relationships break down. While Microsoft has fixed several flaws, the unresolved ones could continue to pose risks. For now, defenders should stay vigilant and ensure their security stacks are resilient against attempts to disable critical updates.
Sources
- BleepingComputer Original source
- UnDefend, Also reporting
- in April Also reporting
Continue Reading
SideCopy Expands Targeting to Indian Academia
Trellix researchers detail a spear-phishing chain abusing mshta.exe and a spoofed document shortcut to deliver the ReverseRAT trojan to academic institutions.
Allies Map North Korea IT Worker Web
A four-nation advisory ties a fake-recruiter hacking crew to North Korea's IT worker scheme and details Japan's first laptop farm takedown.
Provenance Fails as npm Supply Chain Attack Hits
CloudSEK reports attackers abused npm trusted publishing to ship GHAPPIER loader, exposing limits of provenance attestations.