Vulnerabilities · 22h ago

BigDiskBuster Keeps Defender Stuck on Old Signatures

Abdelhamid Naceri, aka Nightmare Eclipse, has now published BigDiskBuster, a public proof of concept that stops Microsoft Defender from completing platform and signature updates. The release shifts the issue from a researcher demo to something other people can copy and adapt.

The trick does not turn Defender off. It waits for an update attempt, then fills the disk so the update cannot finish; once the failure happens, it frees the space and waits for the next try. Defender still looks alive, but its detections stop moving forward, which leaves Windows endpoints running current software with stale protection content.

That matters most in estates that treat the service being on as proof of coverage. Reporting also ties the new tool to an earlier Defender flaw Microsoft patched as CVE-2026-45498, but this public PoC is a separate technique and the sources do not say whether Microsoft has a fix for it yet.

CVE-2026-45498

NVD KEV

Known exploited · CISA KEV

CVSS 4 MEDIUM: microsoft Defender Denial of Service Vulnerability EPSS 63% (99th percentile). Microsoft patch: Release Notes.

CISA federal remediation date Jun 3 · date passed

Timeline

Sources

4 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-23

Editions

Related stories