A new zero-day exploit named BigDiskBuster has been released, targeting Microsoft Defender by preventing it from installing essential platform and signature updates. The tool, publicized by former Microsoft researcher Abdelhamid Naceri, works by occupying all available disk space, which leads to failed update attempts. This lack of updates results in outdated detection content, potentially weakening endpoint protection.
Naceri, dismissed from Microsoft's Security Response Center in 2024, has previously released several exploits affecting Defender. His earlier tools, such as BlueHammer, RedSun, and UnDefend, were exploited in live attacks before Microsoft addressed them. BigDiskBuster uses a novel approach by creating a hidden temporary file that fills the disk space, blocking Defender updates. Despite its buggy nature, Naceri claims it impacts all supported Windows versions, although this has not been independently verified.
There is currently no patch or official advisory from Microsoft regarding BigDiskBuster. Administrators are advised to monitor the system for signs of the exploit, such as frequent update failures or low disk space. Users can check update statuses manually through Windows Security settings or PowerShell commands. Employing application whitelisting tools like Windows Defender Application Control or AppLocker can help prevent unauthorized execution of the tool, offering a layer of defense against potential attacks.

