BigDiskBuster Zero-Day: Unpatched Vulnerability Lets Attackers Block Microsoft Defender Updates on All Windows Versions

BigDiskBuster Zero-Day: Unpatched Vulnerability Lets Attackers Block Microsoft Defender Updates on All Windows Versions

Executive Summary

A new zero-day vulnerability, BigDiskBuster, has been publicly disclosed by a security researcher (also known as Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse). This vulnerability enables attackers to block Microsoft Defender from receiving both platform and signature updates by exploiting disk space exhaustion, effectively rendering Defender’s detection capabilities obsolete over time. There is currently no patch, no CVE, and no official Microsoft advisory for this issue. The proof-of-concept (PoC) exploit was released publicly on GitHub on September 19, 2026, and is already drawing significant attention from the security community due to the researcher’s history of impactful Defender exploits.

Technical Information

BigDiskBuster is a denial-of-service (DoS) vulnerability targeting the update mechanism of Microsoft Defender. The exploit leverages a logic flaw in how Defender handles disk space during update operations. When Defender initiates a platform or definition update, BigDiskBuster creates a hidden temporary file that fills all remaining free disk space on the system drive. This causes the update to fail with a generic Windows error, leaving Defender’s detection content outdated and the endpoint exposed to emerging threats.

The attack is orchestrated as follows: the tool monitors the C:\ drive for new directories under Defender’s update paths. Upon detecting an update attempt, it rapidly fills the disk with a hidden file, causing the update to abort. After Defender removes its staging directory, the tool deletes the temporary file and waits for the next update cycle. Additionally, BigDiskBuster opens a handle on MRT.exe (the Windows Malicious Software Removal Tool), preventing Windows Update from replacing or updating it, which further degrades the system’s security posture.

The PoC is described by the author as “a bit buggy and needs some rewriting,” but is claimed to work on all supported Windows versions. As of this report, there is no independent confirmation of the PoC’s effectiveness, but the researcher’s track record and the technical plausibility of the attack have raised significant concern.

Exploitation in the Wild

There are currently no confirmed reports of BigDiskBuster being used in the wild. However, Previous exploits by this researcher targeting Microsoft Defender—including BlueHammer, RedSun, and UnDefend—were all weaponized in live intrusions before being patched and subsequently added to CISA’s Known Exploited Vulnerabilities catalog. Given the public availability of the PoC and the author’s reputation, there is a high risk of imminent exploitation by both opportunistic attackers and advanced persistent threat (APT) actors.

APT Groups using this vulnerability

At the time of writing, there is no public attribution of BigDiskBuster to any specific APT group or campaign. However, it is important to note that previous exploits by this researcher have been rapidly adopted by threat actors, including those associated with targeted attacks and ransomware operations. The lack of a patch and the ease of exploitation make this vulnerability highly attractive to both financially motivated and state-sponsored actors.

Affected Product Versions

BigDiskBuster affects Microsoft Defender on all supported Windows versions, according to the researcher and corroborated by major cybersecurity news outlets. This includes:

Microsoft Defender Antivirus (formerly Windows Defender Antivirus), Microsoft Defender for Endpoint on all supported Windows client and server versions, including but not limited to Windows 11 (all supported editions), Windows 10 (all supported editions), Windows Server 2022, 2019, 2016 (all supported editions), Windows 8.1 (if still supported by Defender updates), and Windows 7 with ESU (if still supported by Defender updates).

No evidence exists of the vulnerability being limited to specific Defender engine or platform versions. The researcher and all public reporting state "all supported Windows versions" as the affected scope.

Workaround and Mitigation

There is no official patch or vendor workaround for BigDiskBuster at this time. Organizations are advised to implement the following compensating controls:

Restrict execution of unknown binaries using Windows Defender Application Control (WDAC) or AppLocker to prevent attackers from running the PoC or similar tools. Monitor for behavioral indicators such as sudden, unexplained exhaustion of free disk space, repeated Defender update failures, and the presence of large hidden files in Defender’s update directories. Investigate any anomalies immediately. Use PowerShell (Get-MpComputerStatus) to check Defender’s current engine and product versions, and monitor event logs for repeated update failures and low disk space warnings. File system monitoring should be configured to detect the creation of large, hidden files in Defender’s update paths.

Indicators of Compromise

The following caveat applies: Indicators of Compromise (IOCs) are point-in-time and should be validated before enforcement. At the time of writing, no public indicators of compromise (IP addresses, domains, hashes, etc.) have been published for BigDiskBuster. Organizations should focus on behavioral detection as described above.

References

The Hacker News: Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates, Security Affairs: Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day, GBHackers: BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates, MITRE ATT&CK T1499: Endpoint Denial of Service, NVD - No CVE assigned as of 23 September 2026

Rescana is here for you

Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform that empowers organizations to continuously monitor, assess, and mitigate cyber risks across their entire supply chain. Our platform delivers actionable intelligence, automated workflows, and deep visibility into vendor security posture, helping you stay ahead of emerging threats. We are happy to answer any questions at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.