Microsoft Defender BigDiskBuster PoC: local DoS blocks platform/signature updates (MSNightmare / Nightmare Eclipse)
BleepingComputer (Sergiu Gatlan; coverage of weekend disclosure) reports security researcher Abdelhamid Naceri (MSNightmare / Nightmare Eclipse) released BigDiskBuster, a local proof-of-concept that prevents Microsoft Defender Antivirus from completing platform and security-intelligence updates while it runs. The tool watches Defender Platform/Definition Updates directories on the C: volume and starves the installer by creating a hidden delete-on-close temp file sized to remaining free space, with worker threads reclaiming capacity if files change; it may also open MRT.exe with restrictive sharing to interfere with staging. Distinct from desk cards ms-defender-shieldcrash-20260909 / CVE-2026-69414 (ShieldCrash SYSTEM file-read after ShieldBreak). No CVE assigned in the BleepingComputer write-up; Microsoft had not commented at time of reporting. PoC: github.com/MSNightmare/BigDiskBuster. Wire amplify: Cyber Security News 21 Sep 2026.
- Product
- Microsoft Defender Antivirus (platform + security-intelligence / definition update path); Windows
- Versions
- Researcher claims all supported Windows versions; independent verification pending. Unpatched DoS while PoC process runs in background.
- Exploited in Australia?
- unknown
- Patch to
- Monitor Microsoft Defender / Windows security updates for a fix; restrict local untrusted code execution; alert on repeated Defender update failures (e.g. 0x80070643 alone is not proof of this PoC); hunt for BigDiskBuster-like disk-exhaustion against Defender update directories
Primary: BleepingComputer — New Windows Defender zero-day blocks antivirus updates (BigDiskBuster) · Vendor: MSNightmare/BigDiskBuster — PoC repository (MIT) · CVE: CVE-2026-69414 · Cyber Security News — MSNightmare BigDiskBuster DoS (21 Sep 2026)
