HomeYoutubeMicrosoft Defender: New zero-day BigDiskBuster blocks security updates

Microsoft Defender: New zero-day BigDiskBuster blocks security updates

Security researcher Abdelhamid Naceri, known online as Nightmare Eclipse, has created a new headache for Microsoft by publishing yet another proof-of-concept targeting Microsoft Defender. The new zero-day exploit, dubbed BigDiskBuster, is designed to interfere with the update process and prevent the installation of new updates.

The evolution is particularly important, as Defender is a core Windows protection mechanism. When an endpoint remains on older updates, its protection against newer threats can gradually decrease.

What does BigDiskBuster do?

According to the researcher's description, BigDiskBuster is an evolution of the previous UnDefend, which also aimed to block Defender updates.

See also: ShieldCrash: New zero-day for Microsoft Defender

The result is a kind of denial-of-service (DoS) against the update mechanism. This is different from a classic attack that attempts to gain remote control of the computer, but can prove particularly useful in an attack that has already gained local code execution.

Microsoft Defender: New zero-day BigDiskBuster blocks security updates

Why Defender updates are critical

Antiviruses don't rely solely on the original code that is installed on the computer. Continuous updates add new detection data and improvements to the security platform so that the system can identify newer threats.

Therefore, a technique that blocks updates doesn't have to "break" the antivirus to cause a problem. It just leaves it running with outdated protection content, creating a window in which newer malware may have a better chance of going undetected.

The new PoC is not a remote attack in itself

An important point to clarify is that BigDiskBuster is not presented as an exploit that someone can run directly from the internet on a random computer. Available analyses describe it as a local technique, which means that the attacker already needs some level of access or code execution capability on the system.

This limits its role as an initial entry mechanism, but does not eliminate the risk. In a real attack, blocking updates could act as a next stage after the initial breach, allowing an attacker to weaken one of the key defense mechanisms.

A series of zero-days in Defender

BigDiskBuster joins a long line of Naceri disclosures that have sparked heated debate in the cybersecurity community. Since April BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, MiniPlasma, RoguePlanet, LegacyHive, ShieldBreak , and ShieldCrash, with several of the disclosures targeting Defender and other critical Windows components.

Some of these issues have already been addressed by Microsoft. The RoguePlanet case, for example, led to an update to the Microsoft Malware Protection Engine in July.

See also: REVSTEALER: 4 modules disable Windows Defender

Microsoft Defender: New zero-day BigDiskBuster blocks security updates

The dispute with Microsoft continues

The back-to-back publications have taken place in the context of a public confrontation between Naceri and Microsoft over vulnerability management and the researcher's previous relationship with the company.

Microsoft has previously criticized the disclosure of vulnerabilities without prior consultation, and the controversy has sparked a backlash in the security community over the issue of responsible disclosure. The situation becomes even more complex when ready-made PoC code, as the information can be used for both research and defense, as well as malicious purposes.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What should administrators do?

For businesses, this development is a reminder that simply having antivirus enabled is not enough. Administrators should verify that Defender updates are completing properly, monitor failed security intelligence update installations, and investigate unexplained disk space consumption.

See also: Microsoft Defender: False alarm blocks legitimate Google links

At the same time, it is important to limit user rights, keep EDR/XDR tools active where they exist, and log suspicious attempts to interfere with security services. BigDiskBuster, after all, shows a broader trend: attackers don't always need to disable a security solution. They can try to make it less effective.

The new PoC is currently considered experimental, and its code is reportedly buggy, and its effectiveness has not been independently confirmed on all supported versions of Windows. However, its release highlights once again how critical it is to keep a security system up to date, functional, and protected from tampering attempts.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS