CVE-2026-45498
Sfruttamento noto · CISA KEV
CVSS 4 MEDIUM: microsoft Defender Denial of Service Vulnerability EPSS 63% (99º percentile). Patch Microsoft: Release Notes.
Data di correzione federale CISA 3 giu · data superata
Vulnerabilità ed exploit · Exploit zero-day
Abdelhamid Naceri, noto come NightmareEclipse, ha pubblicato BigDiskBuster: un public PoC che impedisce a Microsoft Defender di completare gli update di piattaforma e firme. Il passaggio da ricerca privata a codice riusabile rende il blocco degli update un rischio pratico per gli endpoint Windows.
Il meccanismo è semplice: quando Defender avvia l'update, il tool riempie il disco quel tanto che basta a far fallire l'operazione, poi libera spazio e aspetta il tentativo successivo. Defender continua a girare e sembra sano, ma il contenuto di rilevazione resta indietro; è così che una protezione presente può diventare una protezione vecchia.
Per chi usa Defender come controllo di base sulla flotta Windows, il punto non è la presenza del servizio ma la sua freschezza. Il quadro si aggiunge a CVE-2026-45498, già legata a un precedente blocco degli update, e segnala che la superficie d'attacco resta aperta ogni volta che la detection dipende da un update automatico riuscito.
4 fonti · 22 set
Sfruttamento noto · CISA KEV
CVSS 4 MEDIUM: microsoft Defender Denial of Service Vulnerability EPSS 63% (99º percentile). Patch Microsoft: Release Notes.
Data di correzione federale CISA 3 giu · data superata
The Hacker News
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
BigDiskBuster can block Microsoft Defender updates by filling disk space, leaving detection content stale; no patch or advisory exists.
originaleThe Register Security
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
BigDiskBuster leaves Microsoft's antivirus running but unable to install updates
originaleSecurityWeek
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-09-22
Every edition of this story: Defender resta acceso, ma le firme si bloccano