Security researcher Abdelhamid Naceri has released a new Windows Defender zero-day exploit called BigDiskBuster that prevents the antivirus from receiving platform or signature updates, adding another entry to what has become a prolific and very public campaign against Microsoft. The tool, according to Naceri, works on all supported Windows versions, provided it is kept running in the background.
What BigDiskBuster does and how it works
Naceri, who also goes by the handle Nightmare Eclipse, described BigDiskBuster in his own words as a ‘funny tool’ that ‘completely denies Defender from updating so you’re stuck with your current version if the tool is running in the background.’ He acknowledged the proof of concept is unpolished: ‘PoC is a bit buggy and needs some rewriting but you get the idea.’
The Windows Defender zero-day exploit is modelled on an earlier tool Naceri released called UnDefend, which he published in April and which similarly allowed standard users to block definition updates. BigDiskBuster appears to extend that concept, targeting both platform and signature update channels rather than definitions alone.
According to the Cyber Threat Brief Podcast, BigDiskBuster has been assigned CVE-2026-45498, giving the denial-of-service flaw a formal tracking identifier even as Microsoft has not yet issued a patch. A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out about the zero-day.
A running dispute with Microsoft behind a dozen exploits
BigDiskBuster is not an isolated release. Since April 2026, Naceri has published almost a dozen zero-day exploits as part of an ongoing dispute with Microsoft over what he describes as an unfair termination in March 2025. The list includes LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, targeting Microsoft Defender, BitLocker, and other Windows components.
The pace has been relentless. Two weeks ago, Naceri released ShieldCrash, a Windows Defender zero-day exploit that grants SYSTEM access, timed to land immediately after Microsoft rolled out that month’s Patch Tuesday security updates. ShieldCrash itself was framed as a bypass of ShieldBreak, a Defender privilege escalation flaw Microsoft had patched a week earlier. ShieldBreak, in turn, had bypassed RoguePlanet, a Defender flaw Naceri disclosed in June and Microsoft patched in July.
The pattern is deliberate: each time Microsoft patches one flaw, another appears in the queue. As BleepingComputer has tracked the sequence, it reads less like conventional vulnerability research and more like an organised, sustained pressure campaign.
Microsoft’s response has not helped its standing in the security community. The company initially issued warnings of legal action against anyone engaging in ‘malicious activity causing real harm’ to its customers. Many in the infosec community read that as a direct threat aimed at Naceri, which drew considerable criticism. Microsoft has since patched several of the disclosed flaws, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, but a number of others, BigDiskBuster among them, still have no official fix.
The denial-of-service nature of BigDiskBuster makes it a different category of threat from the privilege escalation exploits Naceri has also released. Blocking Defender updates does not hand an attacker elevated privileges, but it does leave a machine frozen at whatever signature version was current when the tool was first run, potentially for as long as the tool remains active. In a threat landscape where new malware variants appear daily, that gap could matter.
With CVE-2026-45498 now formally assigned and no patch in sight, administrators running affected Windows environments may want to monitor for unusual processes interfering with Defender’s update schedule until Microsoft addresses the BigDiskBuster zero-day through an official security update.

