BigDiskBuster Exploit Freezes Microsoft Defender Updates on All Windows Versions

Security researcher Abdelhamid Naceri, known as Nightmare Eclipse, released a new proof-of-concept exploit called BigDiskBuster that prevents Microsoft Defender from installing platform and signature updates. The tool, published on September 19, 2026, works by filling available disk space to block update downloads on all supported Windows versions. While Defender remains active, its detection capabilities become stale. Microsoft has not issued a patch or CVE for this specific flaw, though it has addressed several other zero-days disclosed by Naceri in recent months. The exploit is part of an ongoing dispute between Naceri and Microsoft over his termination.
Key points
- BigDiskBuster blocks Defender updates by creating hidden files that consume all free disk space on the C: drive.
- The exploit requires the tool to run in the background to continuously prevent update attempts.
- No official Microsoft patch, CVE, or advisory exists for BigDiskBuster as of September 22, 2026.
- Naceri claims the tool works on all supported Windows versions but acknowledges it is currently buggy.
- Administrators can verify Defender status using PowerShell commands or Windows Security settings to detect update failures.
Background
This development follows a series of zero-day disclosures by Naceri since April 2026, including ShieldCrash, ShieldBreak, and UnDefend. Microsoft patched several of these flaws, such as UnDefend (CVE-2026-45498) and ShieldBreak, but others remain unaddressed. In August 2026, Microsoft also issued patches for LegacyHive and addressed phantom 'Defender is off' alerts, highlighting ongoing stability issues with Defender updates. The September 2026 Patch Tuesday resolved a record 974 vulnerabilities, including two actively exploited zero-days, but did not include a fix for BigDiskBuster.
How outlets are covering it
BleepingComputer and The Hacker News focus on the technical mechanism of BigDiskBuster, noting it differs from the earlier UnDefend exploit by using disk space exhaustion rather than resource consumption. SecurityWeek emphasizes the personal background of Naceri, detailing his claims of unfair termination by Microsoft and his subsequent legal battles in Germany. The Register highlights the lack of a vendor response and the potential for stale detection content. All sources agree that no independent researcher has yet confirmed the exploit's behavior, and Microsoft has not commented on the specific BigDiskBuster disclosure.
Why it matters
BigDiskBuster poses a significant risk by forcing organizations to rely on outdated antivirus signatures, potentially leaving systems vulnerable to new threats. The absence of a patch means defenders must rely on manual monitoring and access controls to mitigate the risk. This exploit underscores the ongoing tension between Microsoft and security researchers, as well as the challenges in maintaining up-to-date security software in the face of targeted denial-of-service attacks.
What to watch
Microsoft may issue a patch or advisory for BigDiskBuster in a future update, though no timeline has been announced. Administrators should monitor for repeated Defender update failures and low disk space on system volumes. Independent researchers may attempt to verify the exploit's claims, and CISA may add the vulnerability to its Known Exploited Vulnerabilities catalog if it is observed in the wild. Naceri may continue to release additional exploits as part of his ongoing dispute with Microsoft.
- New Windows Defender zero-day blocks Microsoft antivirus updates BleepingComputer
- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates The Hacker News
- Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity securityweek.com
- NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past The Register
- New Microsoft Defender Zero-Day Blocks Antivirus Security Updates Across Windows LinkedIn
Want the full story? Read the original reporting
Read on BleepingComputer