started · updated
Microsoft Defender targeted by new zero-day exploits
New zero-day vulnerabilities targeting Microsoft Defender have been disclosed, allowing attackers to bypass security protections or gain administrative privileges.
A tool named BigDiskBuster, developed by former Microsoft security researcher Abdelhamid Naceri, exploits a weakness by consuming all available disk space at the moment Defender attempts to download signature or platform updates. This causes the update to fail, leaving the antivirus in an ineffective state without triggering obvious alarms. The tool also targets the Windows Malicious Software Removal Tool to prevent updates.
Separately, a vulnerability in the Microsoft Malware Protection Engine, known as ‘RedSun’, allows attackers to overwrite files with SYSTEM-level privileges. By exploiting flaws in how the engine handles files tagged as cloud-related, an attacker can execute arbitrary code. While patches were released in May 2026, exploit code has been made public, increasing the risk of exploitation. Security experts recommend that users ensure they have applied the latest Microsoft security updates to mitigate these threats.
Entities
Abdelhamid Naceri · CISA · Microsoft · Microsoft Defender · Microsoft Malware Protection Engine