Ethical Hacking News
Chaotic Eclipse has released a new exploit targeting Microsoft Defender, named BigDiskBuster, which triggers a Denial of Service vulnerability in Windows Defender Update. This vulnerability has significant implications for individuals and organizations using Windows Defender to protect their systems. The exploit has been added to the Known Exploited Vulnerabilities catalog by CISA, indicating that it has been identified as a significant threat. With Chaotic Eclipse's history of releasing PoC exploits for zero-day vulnerabilities, this latest release has sparked concerns among security experts about the potential for targeted attacks against organizations using Windows Defender.
The Chaotic Eclipse has released a new exploit, BigDiskBuster, targeting Microsoft Defender, causing a Denial of Service (DoS) vulnerability in Windows Defender Update. The exploit works across supported Windows versions but is currently buggy and needs further development. The vulnerability can render Windows Defender ineffective, preventing platform and signature updates. The exploit is the latest in Chaotic Eclipse's history of releasing PoC exploits for zero-day vulnerabilities, targeting Microsoft products and other anti-malware solutions. The vulnerability has been added to the Known Exploited Vulnerabilities catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), indicating it's a significant threat. Chaotic Eclipse has a controversial past and has been involved in a lengthy legal dispute after being terminated by Microsoft. The release of BigDiskBuster highlights the ongoing threat of zero-day vulnerabilities and the need for vendors to prioritize security and transparency.
Chaotic Eclipse, a security researcher known for publicly releasing proof-of-concept (PoC) exploits for zero-day vulnerabilities, has released a new exploit targeting Microsoft Defender. The exploit, named BigDiskBuster, triggers a Denial of Service (DoS) vulnerability in Windows Defender Update. This vulnerability has significant implications for individuals and organizations using Windows Defender to protect their systems.
According to Chaotic Eclipse, the BigDiskBuster exploit works across supported Windows versions, although the current PoC is still buggy and needs further development. The researcher claims that the technique prevents Windows Defender from performing platform and signature updates, effectively rendering the security software ineffective.
Chaotic Eclipse has a history of releasing PoC exploits for zero-day vulnerabilities, often after criticizing vendors' handling of vulnerability reports. His releases have mainly targeted Microsoft products, including Windows and Microsoft Defender, with some later exploited in the wild. The most notable examples include the Undefend and RedSun Defender zero-days.
The release of BigDiskBuster has sparked concerns among security experts, who warn that this vulnerability could be used to launch targeted attacks against organizations using Windows Defender. The vulnerability has been added to the Known Exploited Vulnerabilities catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), indicating that it has been identified as a significant threat.
Furthermore, Chaotic Eclipse has released PoC exploits for other anti-malware and defense solutions, including Kaspersky Endpoint Security, GenDigital Avast Antivirus, and Crowdstrike Falcon cybersecurity platform. These exploits target privilege escalation flaws, allowing attackers to gain elevated access to systems and potentially disrupting antivirus and file-access controls.
Chaotic Eclipse, whose real name is Abdelhamid Naceri, is a security researcher with a controversial past. He has previously worked with Microsoft in the UK and Germany but was terminated without explanation, leading to a lengthy legal dispute. Naceri has since become known for releasing PoC exploits for zero-day vulnerabilities, often sparking debate over responsible disclosure and the risks of publishing working exploits.
The release of BigDiskBuster and other PoC exploits by Chaotic Eclipse highlights the ongoing threat of zero-day vulnerabilities and the need for vendors to prioritize security and transparency. As the use of zero-day exploits becomes more prevalent, it is essential for organizations to stay vigilant and take proactive measures to protect themselves against these types of attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Chaotic-Eclipses-BigDiskBuster-A-Critical-Windows-Defender-Zero-Day-Vulnerability-ehn.shtml
https://securityaffairs.com/199538/hacking/chaotic-eclipse-released-bigdiskbuster-a-poc-for-windows-defender-update-dos-zero-day.html
Published: Tue Sep 22 09:19:33 2026 by llama3.2 3B Q4_K_M