NightmareEclipse's 'BigDiskBuster' Prevents Microsoft Defender Updates
A new proof-of-concept tool called BigDiskBuster by researcher NightmareEclipse exploits a flaw to prevent Microsoft Defender Antivirus from updating, leaving systems vulnerable.

Security researcher NightmareEclipse, also known as Abdelhamid Naceri, has released a proof-of-concept tool named "BigDiskBuster" that targets Microsoft Defender Antivirus by preventing its essential platform and security intelligence updates. This new exploit, detailed in a recent report, aims to leave Defender installations stuck on outdated versions, potentially exposing users to emerging threats.
According to NightmareEclipse, the tool operates by creating hidden temporary files to consume available disk space, thereby causing Defender's update processes to fail. Once the update failure is detected, the tool cleans up the temporary files, restoring the disk space. This method does not disable Defender entirely but rather cripples its ability to receive crucial threat intelligence, leaving it operating with potentially obsolete detection signatures.
In addition to filling the disk, BigDiskBuster also employs a technique to hold open a handle to Microsoft's Malicious Software Removal Tool (MRT.exe). This action restricts other processes, including Defender's update mechanisms, from accessing the file, further contributing to the update failures. The researcher claims this method is effective across all supported Windows versions, though the current proof-of-concept is noted as being "a bit buggy" and requiring further refinement.
The implications of an un-updated antivirus are significant. While Defender might still be running, its capacity to detect and neutralize new malware strains is severely diminished without the latest threat definitions. This could leave systems susceptible to previously unknown or rapidly evolving threats that would otherwise be caught by up-to-date security intelligence.
This release by NightmareEclipse is part of a continuing pattern of the researcher disclosing Windows vulnerabilities, often accompanied by proof-of-concept code. This behavior stems from a public dispute with Microsoft regarding the company's vulnerability disclosure policies, which the researcher claims have been mishandled. NightmareEclipse has previously released exploits for other Microsoft Defender vulnerabilities, some of which have been patched while others have seen in-the-wild exploitation.
Unlike some previous exploits that offered direct SYSTEM-level privileges, BigDiskBuster focuses on a more insidious form of disruption by targeting a fundamental component of antivirus functionality: its update mechanism. The effectiveness and widespread applicability of this tool across all Windows versions are yet to be independently verified.
As of the report's publication, there is no indication that BigDiskBuster has been used in active, real-world attacks. Microsoft has not yet issued a public statement or response regarding this specific proof-of-concept. The researcher's ongoing disclosures highlight persistent challenges in securing endpoint protection software and the complex relationship between security researchers and software vendors.
The ongoing feud between NightmareEclipse and Microsoft, marked by public disclosures and counter-criticisms, continues to shed light on the intricacies of vulnerability management and responsible disclosure in the cybersecurity landscape. The researcher's prolific output suggests that further exploits targeting Microsoft products may emerge.
This new article provides further technical details on the BigDiskBuster proof-of-concept, including its mechanism of creating hidden temporary files to fill available disk space and blocking the Windows Malicious Software Removal Tool (MRT.exe). It also highlights the researcher's history of disclosing vulnerabilities without vendor coordination and notes that no independent researcher has yet confirmed the tool's behavior.