Microsoft: BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates

Microsoft: BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates

BigDiskBuster PoC Exploits Microsoft Defender Update Mechanism to Degrade Protection

A newly disclosed proof-of-concept (PoC) tool, BigDiskBuster, demonstrates a local denial-of-service (DoS) technique that prevents Microsoft Defender Antivirus from downloading critical updates, potentially leaving Windows endpoints with outdated malware detection capabilities. Released by researcher MSNightmare (also referred to as Nightmare-Eclipse), the tool targets Defender’s update process by manipulating disk space and file handles rather than disabling the antivirus service directly.

The PoC operates by monitoring Defender’s update directories and repeatedly creating hidden temporary files to exhaust available disk space on the system drive. When free space is detected, the tool consumes it again, preventing Defender from staging, unpacking, or installing new platform, engine, or security-intelligence updates. As a result, the antivirus may appear functional but loses the ability to detect emerging threats over time.

Additionally, BigDiskBuster reportedly maintains an open handle on MRT.exe (Microsoft’s Malicious Software Removal Tool) with restrictive permissions, further interfering with file modifications. The tool’s behavior mirrors earlier projects like UnDefend but remains in a developmental stage, with the researcher noting its current implementation is unstable.

Microsoft Defender relies on three key update streams security intelligence (malware signatures), engine updates (scanning logic), and platform updates (core components) all of which are disrupted by the PoC. While the antivirus service remains enabled, its detection efficacy degrades as signatures and engine updates fail to install. Administrators can verify Defender’s status using PowerShell’s Get-MpComputerStatus cmdlet to check installed versions and update timestamps.

The attack requires local execution, meaning an adversary would need prior access to a target system or insider privileges. This limits its use as an initial infection vector but makes it viable for post-compromise defense evasion, particularly for attackers seeking to maintain persistence while avoiding new detections.

As of now, Microsoft has not issued an advisory or assigned a CVE for the reported behavior, and the claims remain unverified by independent validation. Security teams are advised to monitor for unusual disk space depletion, hidden files in temporary directories, and repeated Defender update failures. Unusual process activity targeting Defender’s update paths or retaining handles on protected binaries may also indicate exploitation attempts.

Organizations can validate endpoint protection by reviewing Defender’s operational logs, signature timestamps, and platform version alignment with deployment baselines. Application control policies, such as Windows Defender Application Control (WDAC) or AppLocker, may mitigate risks by restricting untrusted binaries from executing in user-writable locations.

Source: https://cyberpress.org/bigdiskbuster-windows-defender-dos-vulnerability/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security

"id": "mic1789986463",
"linkid": "microsoft-security",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Windows endpoint users',
                        'industry': 'Cybersecurity',
                        'name': 'Microsoft Defender Antivirus',
                        'type': 'Antivirus Software'}],
 'attack_vector': 'Local Execution',
 'description': 'A newly disclosed proof-of-concept (PoC) tool, '
                '*BigDiskBuster*, demonstrates a local denial-of-service (DoS) '
                'technique that prevents Microsoft Defender Antivirus from '
                'downloading critical updates, potentially leaving Windows '
                'endpoints with outdated malware detection capabilities. The '
                'tool targets Defender’s update process by manipulating disk '
                'space and file handles rather than disabling the antivirus '
                'service directly.',
 'impact': {'operational_impact': 'Degraded malware detection capabilities due '
                                  'to outdated signatures and engine updates',
            'systems_affected': 'Windows endpoints with Microsoft Defender '
                                'Antivirus'},
 'lessons_learned': 'Local DoS techniques can degrade endpoint protection '
                    'without disabling antivirus services directly. Monitoring '
                    'for unusual disk space depletion and process activity is '
                    'critical for detecting such attacks.',
 'motivation': 'Proof-of-Concept / Research',
 'post_incident_analysis': {'corrective_actions': 'Implement application '
                                                  'control policies and '
                                                  'enhanced monitoring for '
                                                  'Defender update processes.',
                            'root_causes': 'Exploitation of Microsoft '
                                           'Defender’s update mechanism via '
                                           'disk space exhaustion and file '
                                           'handle manipulation.'},
 'recommendations': ['Implement application control policies (e.g., WDAC or '
                     'AppLocker) to restrict untrusted binaries.',
                     'Monitor Defender’s update logs and signature timestamps '
                     'for anomalies.',
                     'Review process activity for handles on protected '
                     'binaries like MRT.exe.',
                     'Validate endpoint protection by ensuring Defender’s '
                     'platform, engine, and security-intelligence updates are '
                     'current.'],
 'references': [{'source': 'Researcher MSNightmare (Nightmare-Eclipse)'}],
 'response': {'containment_measures': 'Monitor for unusual disk space '
                                      'depletion, hidden files in temporary '
                                      'directories, and repeated Defender '
                                      'update failures. Review Defender’s '
                                      'operational logs, signature timestamps, '
                                      'and platform version alignment.',
              'enhanced_monitoring': 'Monitor for unusual process activity '
                                     'targeting Defender’s update paths or '
                                     'retaining handles on protected binaries.',
              'remediation_measures': 'Application control policies (e.g., '
                                      'Windows Defender Application Control '
                                      '(WDAC) or AppLocker) to restrict '
                                      'untrusted binaries from executing in '
                                      'user-writable locations.'},
 'threat_actor': 'MSNightmare (Nightmare-Eclipse)',
 'title': 'BigDiskBuster PoC Exploits Microsoft Defender Update Mechanism to '
          'Degrade Protection',
 'type': 'Denial-of-Service (DoS)',
 'vulnerability_exploited': "Exploitation of Microsoft Defender's update "
                            'mechanism via disk space and file handle '
                            'manipulation'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.