New Windows Defender zero-day blocks Microsoft antivirus updates

MediumBleepingComputer · Sergiu Gatlan·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
MicrosoftWindows
Reported by
1 outlet

Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.

Naceri named it BigDiskBuster and said it is similar to another Defender zero-day known as UnDefend, which he released in April and that allowed standard users to block definition updates.

The security researcher added that BigDiskBuster works on all supported Windows versions and that it needs to run in the background to block Defender updates.

"Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background," he said.

"This proof of concept is similar to UnDefend, it prevents windows defender from performing platform/signature updates. Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea."

Since April 2026, Naceri, who claims to be a former Microsoft employee, has released almost a dozen zero-day exploits as part of an ongoing dispute with Microsoft over their alleged unfair termination in March 2025.

Naceri also released several zero-day exploits that allowed privilege escalation on various Windows versions five years ago.

Two weeks ago, they released another Defender zero-day exploit that grants SYSTEM access (known as 'ShieldCrash') right after Microsoft rolled out this month's Patch Tuesday security updates.

According to Naceri, ShieldCrash bypasses another ShieldBreak Defender privilege escalation flaw patched a week earlier, which itself bypassed RoguePlanet, another Defender flaw the security researcher disclosed in June and Microsoft patched in July.

Naceri's zero-day exploits released this year also include LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, which target Microsoft Defender, BitLocker, and other Windows components.

Microsoft initially responded with warnings of legal action against anyone engaging in "malicious activity causing real harm" to the company's customers, leading many in the infosec community to believe that Microsoft was directly threatening the security researcher.

While Microsoft has fixed some of the security flaws Naceri disclosed (such as ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws), the other security issues still lack an official patch.

A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out about the BigDiskBuster denial-of-service zero-day.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Reproduced in full under licence from BleepingComputer. © BleepingComputer. Written by Sergiu Gatlan.

Coverage

One outlet has carried this so far.

  1. BleepingComputerEstablished SourceFirst reported

    2026-09-22 09:55 UTC

Related stories

New Windows Defender zero-day blocks Microsoft antivirus updates | CyberBrief