CVE Tools

Patch for Windows Defender 0-day could allow attackers to fill hard disk

Ars Technica (Security)By Dan Goodin

PoC publicWindows Defender

Our summary

Microsoft has issued a patch for a critical zero-day vulnerability in its Windows Defender security engine, identified as CVE-2026-50656. The flaw was publicly disclosed in June by an anonymous researcher using the alias NightmareEclipse, who also shared proof-of-concept code for exploitation. This vulnerability enables remote attackers to gain administrative access on Windows 10 and 11 systems, even if real-time protection is turned off. According to the researcher, the latest update introduces changes that could allow malicious actors to fill up hard drives by generating large volumes of data. Microsoft claims the fix will be automatically applied through an update to the Malware Protection Engine.

Read at Ars Technica (Security)

Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store