Microsoft Defender Zero-Day Lets Standard Users Block Antivirus Updates
Security researcher Abdelhamid Naceri, also known as Nightmare Eclipse, has released another Microsoft Defender zero-day exploit that can prevent antivirus definition updates.
Named BigDiskBuster, the proof-of-concept exploit is similar to UnDefend, another Microsoft Defender zero-day released by Naceri in April. Unlike some previous exploits, BigDiskBuster reportedly allows standard Windows users to block Defender updates.
Naceri said BigDiskBuster works on all supported Windows versions. However, the tool must continue running in the background to prevent Microsoft Defender from receiving new updates.
“We’ve created an interesting tool that completely refuses to update Defender, so if the tool is running in the background, you’ll be stuck with the current version,” Naceri said.
According to the researcher, the proof of concept prevents Windows Defender from performing platform and signature updates. He also noted that the current version is buggy and requires additional rewriting.
Naceri releases a series of Windows zero-days
Since April 2026, Naceri has released nearly a dozen zero-day exploits as part of an ongoing dispute with Microsoft over his alleged unfair dismissal in March 2025. The researcher has targeted Microsoft Defender, BitLocker, and other Windows components.
Two weeks ago, Naceri released another Microsoft Defender zero-day known as ShieldCrash, which reportedly grants SYSTEM access. The release came shortly before Microsoft issued its latest Patch Tuesday security updates.
Naceri said ShieldCrash bypasses ShieldBreak, a Microsoft Defender privilege-escalation flaw patched one week earlier. ShieldBreak itself reportedly bypassed RoguePlanet, another Defender vulnerability disclosed by security researchers in June and patched by Microsoft in July.
Other zero-day exploits released by Naceri this year include LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend.
Microsoft has patched some reported vulnerabilities
Microsoft initially responded to Naceri’s disclosures and issued a warning about potential legal action. Members of the information security community said the company was directly threatening security researchers who engage in activities that could cause actual harm to customers.
Microsoft has fixed some of the vulnerabilities disclosed by Naceri, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma. Other reported security issues still do not have official patches.
Microsoft did not respond to BleepingComputer’s request for comment about the BigDiskBuster Microsoft Defender zero-day.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



