BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates

A newly published proof-of-concept (PoC), dubbed BigDiskBuster, claims to prevent Microsoft Defender Antivirus from downloading both platform and security-intelligence updates, potentially leaving affected Windows endpoints with increasingly outdated detection coverage.

A researcher released the tool as MSNightmare/Nightmare-Eclipse and describes it as a local denial-of-service technique rather than a remote code-execution flaw.

Its GitHub documentation says the PoC is similar to the earlier UnDefend project and may work across supported Windows releases, although the author cautions that the current implementation is buggy and requires further development.

BigDiskBuster Windows Defender DoS Vulnerability

BigDiskBuster reportedly monitors Defender update-related activity, including directories used for platform and definition updates.

When it detects relevant filesystem changes, the PoC checks free space on the system drive and creates a hidden temporary file intended to consume nearly all remaining capacity. It repeats the process when disk space becomes available again.

The effect is intended to deny Defender’s update mechanism enough available local storage to stage, unpack, and install new packages. The researcher’s PoC does not claim to disable the Microsoft Defender Antivirus service or turn off real-time protection directly.

Instead, it aims to make update operations fail persistently, leaving the installed engine, platform components, and malware signatures frozen at their current versions.

BigDiskBuster (Source: MSNightmare)
BigDiskBuster (Source: MSNightmare)

BigDiskBuster also reportedly keeps a handle open on MRT.exe, the Microsoft Malicious Software Removal Tool executable, with restrictive sharing permissions. That behavior may interfere with attempts to replace, modify, or remove the file while the handle is retained.

Microsoft Defender relies on several update streams with separate security functions:

Update typeSecurity rolePotential impact if blocked
Security intelligenceAdds malware detections, indicators, and cloud-protection logicNew threats may evade static detection
Engine updatesUpdates the scanning engineDetection and remediation capabilities may lag
Platform updatesRefreshes Defender components and servicing codeReliability and security fixes may not install

MSNightmare stated that a device can therefore appear protected because Defender remains enabled while its ability to identify recently emerging malware deteriorates over time.

This distinction matters for defenders: a healthy antivirus service does not necessarily mean signature freshness or platform servicing is working correctly.

Microsoft administrators can inspect Defender status through Get-MpComputerStatus, including the installed product version and signature-update timing.

The available reporting indicates BigDiskBuster is a local PoC. An attacker would need prior code execution on a target, or a malicious insider would need the ability to run the tool.

That constraint limits its role as an initial-access vector but makes it relevant to post-compromise defense evasion, especially where attackers want to preserve persistence and reduce the chance that new detections identify their tooling.

The claims should be treated as researcher-reported until independently reproduced and addressed by Microsoft. No Microsoft advisory or CVE assignment was identified in the available material.

Organizations should monitor for sustained low-free-space conditions on endpoint system volumes, unexpected large hidden files in temporary directories, and repeated Defender update failures.

Security teams should also alert on unusual processes accessing Defender update paths or retaining handles on protected Microsoft binaries.

Administrators can validate whether endpoints are receiving current protection by reviewing Defender Operational logs, checking signature timestamps, and confirming that installed Defender platform versions match approved deployment baselines.

Where feasible, application-control policies such as WDAC or AppLocker can reduce the ability of standard users to execute untrusted binaries from temporary and user-writable locations.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories