A newly released proof-of-concept tool dubbed BigDiskBuster can stop Microsoft Defender Antivirus from receiving platform and signature updates by deliberately exhausting disk space on Windows systems, while the antivirus service continues to appear healthy to administrators.[10][14][15] Security researcher Nightmare Eclipse, also known as Chaotic Eclipse and MSNightmare, published the BigDiskBuster code as a Windows Defender update denial-of-service technique, and at the time of writing there is no CVE, no vendor patch, and no dedicated Microsoft security advisory addressing the issue.[1][2][6][9]
BigDiskBuster works by rapidly filling the system drive C: with a large temporary file precisely when Microsoft Defender attempts to download new security intelligence or platform updates, forcing the operation to fail with generic error 0x80070643 before quietly deleting the file and freeing disk space again.[10][14][15] As a result, Defender continues to run and report as enabled, but its malware signatures and engine remain out of date, creating what the researcher describes as a persistent detection gap that does not rely on exploiting a traditional memory corruption bug.[10][15] The tool is also reported to interfere with the Microsoft Malicious Software Removal Tool (MRT.exe), further weakening built-in remediation capabilities on affected endpoints.[15] Nightmare Eclipse claims the technique impacts all currently supported Windows versions, but multiple outlets note that this affected-version assessment has not been independently validated and that Microsoft has not formally recognized BigDiskBuster as a vulnerability.[9][13][14]
The release continues a pattern of public friction between the researcher and Microsoft, following earlier Defender-focused proofs-of-concept such as UnDefend, which silently degraded Defender’s threat intelligence while showing endpoints as healthy in management consoles.[1][12] Microsoft ultimately addressed UnDefend in May 2026, assigning CVE-2026-45498 to the issue and delivering a fix in Antimalware Platform version 4.18.26040.7, closing off that attack avenue.[3][8][12] BigDiskBuster is described by its author as “similar to UnDefend,” in that it targets Defender’s ability to update rather than its scanning logic, but unlike UnDefend it currently lacks an official vulnerability designation or documented remediation from Microsoft.[1][3][5]
Public reporting indicates that BigDiskBuster’s implementation is still considered “buggy” even by its creator and that the code may require refinement to work reliably across diverse environments, underscoring that this is a researcher tool rather than a polished weaponized exploit.[1][14] Nonetheless, the PoC is available to anyone who can download and run it, and several outlets highlight that there is no evidence so far of BigDiskBuster being used in real-world attacks even as the publication of source code lowers the barrier for potential abuse or adaptation by threat actors.[2][9][15] Because BigDiskBuster focuses on exhausting local disk space during updates, a successful attack would still require the ability to execute code on the target endpoint, but in scenarios where an adversary already has that foothold the tool could be chained with other techniques to keep Defender blind to evolving malware campaigns.[5][6][12]
For defenders, the immediate concern is less about a remote “wormable” exploit and more about silent degradation of endpoint protection: systems can show Microsoft Defender as running yet fail to ingest new signatures or engine versions, leaving organizations exposed to newer threats without obvious red flags in standard dashboards.[10][14][15] Security teams are urged by coverage in outlets such as The Hacker News, Security Affairs, and Shattered.io to closely monitor Defender update logs for repeated 0x80070643 failures, baseline minimum free disk space on critical servers and workstations, and investigate endpoints whose Defender engine or definition versions lag behind expected baselines for extended periods.[2][5][6][15] Given Microsoft’s past response to UnDefend, researchers and enterprises alike expect the vendor to eventually clarify its position and, potentially, release a fix or mitigation guidance, but until that happens BigDiskBuster remains an unpatched proof-of-concept technique capable of turning a simple disk-space manipulation into a long-lived antivirus blind spot.[1][3][5]
References
- BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)
- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
- BigDiskBuster: PoC Blocks Microsoft Defender Updates
- BigDiskBuster PoC Blocks Windows Defender Updates
- Chaotic Eclipse Released BigDiskBuster, A PoC For …
- BigDiskBuster: PoC blockiert Updates von Microsoft Defender
- BigDiskBuster blocca gli aggiornamenti di Microsoft Defender senza spegnerlo – Matrice Digitale
- Ex-Microsoft-Mitarbeiter enttarnt Sicherheitslücke, die Updates verhindert –„Habe ein lustiges Tool entwickelt“
- Microsoft Defender Triple Zero-Day: BlueHammer, RedSun …
- BigDiskBuster: Public PoC Claims to Block Microsoft Defender …
- BigDiskBuster PoC Claims Defender Update DoS via Disk …
- Nightmare Eclipse fait des misères à Microsoft Defender en mode bourrin