Microsoft has fixed a bug that caused Microsoft Defender Antivirus to crash and display a 0xc0000005 access violation error on some Windows systems after a recent security update.
Microsoft Defender is built-in security software that provides real-time protection against malware, viruses, ransomware, and spyware across Windows, macOS, Linux, Android, and iOS devices.
According to reports shared on social media and Microsoft’s Support site, affected users began seeing the “Threat Service has stopped. Please restart now” error on Windows 10 and Windows 11 devices Tuesday afternoon. In some cases, the problem prompted customers to consider reinstalling their operating systems.
The issue prevented Microsoft Defender from completing quick and full scans. In some cases, the Defender service had to be restarted before users could try scanning again.
“Starting this morning, quick scans and full scans have been failing, sometimes to the point where the Defender service needs to be restarted,” one Windows system administrator said.
“We encountered this issue while responding to another infection. We initially thought Defender had been interrupted by the infection, but we were able to reproduce the problem on other devices simply by starting a quick scan.”

Microsoft confirmed the Microsoft Defender scanning problem and said it was resolved through a new security intelligence, or signature, update.
A Microsoft spokesperson told BleepingComputer: “We are addressing this issue with a fix and recommending customers apply the latest update or enable automatic updates.”
The fix is delivered automatically through Microsoft Defender Antivirus Security Intelligence Update version 1.457.236.0 or later.
Users affected by the Defender crash or the “Threat Service has stopped” error should install the latest updates through Windows Update and confirm that the newest Microsoft Defender Security Intelligence updates are installed. Enabling automatic updates can help ensure the fix is applied without manual intervention.
Microsoft Defender has experienced other issues in recent months. In May, system administrators reported that Microsoft Defender incorrectly flagged DigiCert root certificate entries as Trojan:Win32/Cerdigent.A!dha malware. The false positives triggered widespread alerts and, in some cases, caused certificates to be removed from the Windows trust store.
Earlier, in December 2025, a major Microsoft Defender portal outage blocked access to some Defender XDR features and disrupted threat-hunting alerts.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




