Microsoft has resolved the Windows Defender scan crashes that began hitting Windows 10 and Windows 11 machines after a security update, pushing a fix through signature update version 1.457.236.0. The trouble announced itself bluntly: affected users saw “Threat service has stopped. Restart it now” error messages and 0xc0000005 access violation errors, with quick and full scans failing repeatedly and, in some cases, taking the Defender service down with them.
Reports surfaced on social media and Microsoft’s support site from Tuesday afternoon onwards. The scale of disruption was wide enough that some affected customers resorted to reinstalling the operating system entirely, before Microsoft confirmed the issue and directed users toward the signature update.
Windows Defender scan crashes spread to freshly installed machines
The scope of the problem went beyond poorly maintained or already-compromised endpoints. According to Windows Forum, Defender for Endpoint administrators on r/sysadmin reported MsMpEng.exe crashes across multiple endpoints, including machines that had been freshly installed, ruling out local infection or configuration drift as the cause. One Windows system admin described the experience in plain terms: “Beginning this morning, quick or full scans are failing, and will occasionally fail to the point where the Defender service needs to be restarted. We came across this while responding to a separate infection, I chalked it up to Defender being borked due to the infection but then I was able to recreate the issue on other devices simply by initiating a Quick Scan.”
That last detail is the telling one for any sysadmin trying to triage: the crash was reliably reproducible on clean systems, which meant the security update itself was the common factor, not anything on the endpoint.
Fix rolled out in stages, with some systems needing a second update
Microsoft told BleepingComputer that it had addressed the problem and recommended customers apply the latest update or enable automatic updates. “We have addressed this with a fix and recommend customers apply the latest update or enable automatic updates,” a Microsoft spokesperson said. The fix is applied automatically after installing Microsoft Defender Antivirus signature update version 1.457.236.0 or later. Affected users can also trigger it manually through Windows Update, then verify that the latest security intelligence update is installed.
In practice, the rollout was not entirely clean. User testing on 19 August, reported by Windows Forum, found that version 1.457.236.0 restored scan functionality on some systems, but others continued to fail until version 1.457.238.0 or a newer package arrived. Administrators dealing with large fleets should confirm which version is actually installed rather than assuming the first update resolves everything across the board.
As for what triggered the crash in the first place, the picture remains murky. Windows Forum notes there is currently no published evidence tying the 18 August scan crash to a ShieldBreak mitigation, an engine patch, or any other specific security fix, so the root cause, whatever it was, has not been publicly identified by Microsoft.
Not the first stumble for Defender in recent months
This episode is the latest in a run of Defender-related disruptions. In May, system administrators reported that Microsoft Defender flagged DigiCert root certificate entries as Trojan:Win32/Cerdigent.A!dha malware, generating widespread false-positive alerts and, in some cases, removing certificates from the Windows trust store. Before that, in December 2025, a widespread Microsoft Defender portal outage blocked access to certain Defender XDR portal capabilities and disrupted threat hunting alerts.
Three separate incidents in the space of several months is an uncomfortable pattern for a product that sits at the centre of security operations on Windows endpoints. For now, administrators who have not yet applied the update should do so, verify the installed version, and check whether 1.457.238.0 is available if scans are still failing after the initial update.

