New Defender Flaw Blocks Antivirus Updates on All Windows Versions

Researcher releases BigDiskBuster, a tool that prevents Windows Defender from updating, leaving systems with outdated protections.
Key points
- BigDiskBuster is a zero-day flaw that blocks Microsoft Defender from updating on all supported Windows versions.
- The tool must run in the background to prevent the download of new security definitions and platform updates.
- The exploit is part of a series of disclosures by researcher Abdelhamid Naceri, some of which remain unpatched by Microsoft.
A new security flaw in Microsoft Defender allows users to prevent the antivirus software from receiving critical updates. The exploit, dubbed BigDiskBuster, was released by security researcher Abdelhamid Naceri and affects all currently supported versions of Windows.
If the tool is kept running in the background, it stops Defender from downloading platform and signature updates. This leaves the system stuck with its current version of protection, potentially exposing it to newly discovered threats that have already been patched in newer definitions.
Update blocking remains active
Naceri describes BigDiskBuster as a proof-of-concept similar to an earlier flaw called UnDefend, which he disclosed in April. While the current version is described as buggy, it demonstrates that standard users can deny Defender the ability to refresh its security database.
The trade-off for users who run this tool is significant. By blocking updates, they lose protection against the latest malware variants. This creates a window of vulnerability where the system remains exposed to new attacks that the outdated definitions cannot detect.
Part of ongoing dispute
This release is part of a broader series of zero-day exploits Naceri has published since early 2026. The researcher claims these disclosures are related to a dispute with Microsoft over their termination in March 2025.
In the past two months, Naceri has released multiple flaws, including ShieldCrash, which grants system-level access. Microsoft has patched some of these issues, such as ShieldBreak and RoguePlanet, but others remain unaddressed according to the researcher.
Microsoft response unclear
Microsoft previously warned of legal action against malicious activity causing harm to customers, a statement that many in the security community interpreted as a threat toward the researcher. BleepingComputer reported that a Microsoft spokesperson was not immediately available to comment on the new BigDiskBuster flaw.
The situation highlights a tension between security researchers and vendors. While rapid patching is ideal, the gap between disclosure and fix leaves a risk period. Users should ensure their systems are updated and avoid running unverified tools that interfere with security services.






