Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 19, 2026, Abdelhamid Naceri published BigDiskBuster on GitHub, a proof-of-concept that blocks Microsoft Defender platform and signature updates by systematically consuming available disk space. The antivirus service remains running with real-time protection active, but malware definitions stay obsolete. No CVE, patch, or Microsoft advisory currently resolves the technique, which operates with standard user privileges.
- The BigDiskBuster PoC, published September 19, 2026 by Abdelhamid Naceri (alias NightmareEclipse), blocks Microsoft Defender platform and signature updates without disabling the service
- The mechanism monitors the C:\ filesystem for Defender update activity, creates a hidden temporary file that consumes nearly all remaining free space, and repeats the cycle to keep definitions stale
- LevelBlue independently reproduced the PoC successfully on standard installations, confirming execution requires only standard user privileges
- Microsoft stated Defender includes "detections and preventions against the PoC" but has not issued a CVE, patch, or dedicated advisory; the prior similar tool UnDefend was patched as CVE-2026-45498 via a different mechanism
How the Silent Block Works
BigDiskBuster exploits an implicit assumption in Microsoft Defender's update pipeline: that sufficient disk space exists to complete definition downloads and installation. The roughly 300 lines of C++ combine four mechanisms: raw device handle opening, relative file open, recursive volume monitoring, and oversized allocation.
According to the independent reproduction by Serhii Melnyk and Timmy Lister of LevelBlue, the PoC watches the C:\ volume for activity related to Defender updates. When it detects the operation, it creates a hidden temporary file sized to consume essentially all remaining free space. The update fails due to insufficient space; the cycle repeats on the next attempt, keeping definitions indefinitely at their current version.
Naceri described the result in explicit terms: "completely denies defender from updating so you're stuck with your current version if the tool is running in the background." The hidden file is removed and recreated, making the mechanism resiliently cyclic without manual intervention.
The PoC also interferes with the Windows Malicious Software Removal Tool: it opens a handle on MRT.exe to block its replacement via Windows Update, extending the blockade beyond antivirus definitions alone.
Why an "Active" Defender Is More Dangerous Than a Disabled One
The most insidious characteristic of BigDiskBuster is that it does not stop the Defender service or disable real-time protection. The endpoint continues to report a green health status; monitoring dashboards show the antivirus as active and functioning. Only the definitions lag behind.
"The important part is what does not happen. Defender's service keeps running, and real-time protection remains active. There is no obvious product failure — only an update process that quietly stops keeping the endpoint current" Serhii Melnyk and Timmy Lister, LevelBlue
This condition — which LevelBlue researchers termed a "silent detection gap" — makes the technique particularly suited for windows of opportunity for malware that already possesses known evasions. A threat actor does not need to bypass Defender in real time; they simply wait for definitions to become obsolete enough to miss their payload. In this scenario, the misleading health indicator becomes actively harmful.
Context: An Author with Priors and a Recurring Pattern
Abdelhamid Naceri, known as NightmareEclipse or MSNightmare, is a former Microsoft Security Response Center employee terminated in 2024. Since April 2026 he has released exploits without coordinated disclosure, with a sequence of tools that repeatedly targeted the same attack surface.
Before BigDiskBuster, Naceri published BlueHammer, RedSun, and UnDefend. The prior tools were exploited in real intrusions before Microsoft released corresponding patches. UnDefend in particular — which exploited an "uncontrolled resource consumption" mechanism to interfere with Defender — was fixed by Microsoft in May 2026 as CVE-2026-45498, with CVSS 4.0 (MEDIUM) and an Antimalware Platform update to version 4.18.26040.7 per the official advisory.
BigDiskBuster uses a technically different mechanism, however: not uncontrolled resource consumption, but controlled and cyclic allocation of free space. Sources converge in considering it unlikely that the UnDefend patch also covers the new PoC, but Microsoft has not confirmed this assessment.
Naceri claimed the tool "seems to work on all supported Windows versions," also noting the code is "a bit buggy and needs some rewritting." This universal compatibility claim has not been independently verified.
What to Do Now
Given the absence of a dedicated Microsoft patch or advisory, organizations must intensify proactive monitoring of Defender definition freshness, treating it as an essential security control rather than a secondary operational parameter.
- Monitor error code 0x80070643 in Defender updates: its repetition constitutes a primary indicator of possible BigDiskBuster activity, per LevelBlue
- Check definition versions more frequently than usual: compare the signature version reported by Defender against the version officially distributed by Microsoft to detect anomalous gaps
- Observe handle and disk allocation activity on sensitive endpoints: hidden temporary files suspiciously sized near remaining free space, combined with open handles on Defender processes and MRT.exe, provide a specific compromise signal
- Verify the prior CVE-2026-45498 patch: ensure the Antimalware Platform is updated to at least version 4.18.26040.7 to mitigate UnDefend, recognizing this does not resolve BigDiskBuster
Independent reproductions confirm the technique requires no administrative privileges: any compromised user account can execute it, significantly expanding the risk surface.
Microsoft Statements and Dossier Limits
A Microsoft spokesperson told Dark Reading that "Microsoft Defender Antivirus includes detections and preventions against the PoC," without specifying the technical nature of these countermeasures or confirming whether they are effective against all possible code variants. The same source added the generic advice to "keep Microsoft Defender security intelligence and platform updates current and update to the latest available security intelligence" — a recommendation that BigDiskBuster's mechanism makes inherently difficult to follow on already-compromised endpoints.
The dossier does not establish whether Microsoft's stated "detections and preventions" are currently in universal distribution or limited to specific update channels. It is also undocumented whether BigDiskBuster has already been used in real attacks, nor when or if Microsoft will issue a dedicated CVE, patch, or advisory. The original GitHub code appears to have been removed per some sources, but availability in other forms is unverifiable.
The Lesson of the Security False Positive
BigDiskBuster exemplifies a category of attack that security teams tend to underestimate: one that does not compromise the security service, but its utility. The belief that "Defender is active, therefore the endpoint is protected" becomes in this case an actively exploitable bias. For SOCs, the relevant metric is no longer service status, but the date of the last successfully updated definition — an operational datum that must rise to the level of a risk indicator.
Naceri's sequence of tools, each refined against the same Windows security infrastructure, suggests that Defender's attack surface — understood as the ecosystem of update and maintenance, not just the detection engine — deserves the same attention traditionally reserved for the kernel or drivers.
Sources
- https://www.darkreading.com/application-security/bigdiskbuster-microsoft-defender-running-blocking-updates
- https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html
- https://shattered.io/bigdiskbuster-poc-blocks-defender-updates-2026/
- https://tech-insider.org/bigdiskbuster-defender-zero-day-no-cve-2026/
- https://www.theregister.com/security/2026/09/22/nightmareeclipses-latest-zero-day-leaves-microsoft-defender-stuck-in-the-past/5298320
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.