NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself.
The security researcher, also known as Abdelhamid Naceri, released a proof-of-concept dubbed “BigDiskBuster” that is designed to prevent Microsoft Defender Antivirus from installing platform and security intelligence updates.
“Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background,” NightmareEclipse said.
The researcher describes BigDiskBuster as similar to their earlier “UnDefend” tool and claims it works on all supported versions of Windows, although they admit the current PoC is “a bit buggy and needs some rewritting [sic].” That compatibility claim has not been independently verified.
The trick doesn't disable Defender.
Instead, the PoC waits for an update to start, then tries to fill up the drive so there isn't enough space for it to finish.
The code does this by creating hidden temporary files sized to consume the drive's free space, spinning up additional threads as needed to claim more.
Once it detects that the Defender update has failed, it closes the files and returns the space.
BigDiskBuster also opens Microsoft's Malicious Software Removal Tool executable, MRT.exe, in a way that restricts other processes' access to the file while the handle remains open.
The result, according to NightmareEclipse, is that Defender stays stuck on its current platform and security intelligence versions as long as the tool keeps interfering with updates.
A screenshot published alongside the PoC shows Windows Security reporting that a protection definition update failed with error 0x80070643.
That's a generic installation error, however, and isn't evidence on its own that BigDiskBuster is at work.
Leaving Defender stuck on old security intelligence is obviously less than ideal.
The antivirus may still be running, but preventing it from receiving Microsoft's latest threat definitions could leave it less able to identify newly detected malware.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.