---
title: New zero-day exploit blocks Microsoft Defender updates
url: https://www.dataloco.com/en/new-zero-day-exploit-blocks-microsoft-defender-updates
published: 2026-09-25T18:21:15+00:00
language: en
section: Security
source: https://www.it-connect.fr/bigdiskbuster-zero-day-defender-bloque-mises-a-jour/
organizations: Microsoft, GitHub
publisher: Dataloco
---

# New zero-day exploit blocks Microsoft Defender updates

A new zero-day exploit named BigDiskBuster has been published, preventing Microsoft Defender from installing security updates. The tool, released by the researcher known as Nightmare Eclipse, causes the antivirus software to remain on its current version by simulating a full storage drive. This denial-of-service attack does not grant elevated privileges but stops the automatic update process for the antivirus definitions.

The exploit was made available on GitHub over the weekend. Nightmare Eclipse, whose real name is Abdelhamid Naceri, stated that the tool works on all versions of Windows. He described the exploit as a fun tool that completely prevents Defender from updating, leaving users stuck with their current version if the tool runs in the background. The researcher noted that the code does not appear to require administrator rights, suggesting that a standard user account might be sufficient to execute the attack.

This release is part of a series of zero-day exploits targeting Windows that Naceri has published since April 2026. He has released nearly a dozen such exploits during a period of conflict with Microsoft. Naceri recently revealed his identity and shared his account of being dismissed from Microsoft. His previous release, ShieldCrash, was published two weeks ago, shortly after the September 2026 Patch Tuesday. ShieldCrash bypassed the fix for ShieldBreak to read any file with SYSTEM privileges.

The new BigDiskBuster exploit is described as being similar to UnDefend, an exploit released in April 2026. UnDefend allowed a standard user to block Defender definition updates. The UnDefend vulnerability was previously exploited in real cyberattacks alongside BlueHammer and RedSun. BigDiskBuster works by deceiving Microsoft Defender into believing the local storage is full. Defender checks available storage space before updating and cancels the operation if the drive is full. The exploit manipulates this check to halt the update process.

While BigDiskBuster alone does not compromise a machine, it weakens defenses by leaving the antivirus with outdated signatures. This reduces the ability to detect recent threats. The exploit is currently available on GitHub. It does not have a CVE reference, and no patch has been released. Microsoft has not yet reacted to the disclosure. The vulnerability may be addressed in the upcoming Patch Tuesday in October 2026.
