Securityaffairs

Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day


Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

Pierluigi Paganini
September 22, 2026

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability.

Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update.

The security researcher claims to have developed BigDiskBuster, a proof-of-concept that can block Microsoft Defender from receiving platform and signature updates.

“This proof of concept is similar to UnDefend, it prevents windows defender from performing platform/signature updates.” wrote the expert. “Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea.”

Chaotic Eclipse says the technique works across supported Windows versions, although the current PoC is still buggy and needs further development.

In September, Chaotic Eclipse released multiple zero-day exploits targeting Nvidia (GreenSection) and Microsoft Defender (ShieldCrash).

Recently, Chaotic Eclipse also released exploits targeting other anti-malware and defense solutions. Chaotic Eclipse released a zero-day exploit targeting Kaspersky Endpoint Security he named HardBreacher, which triggers a privilege escalation flaw. The researcher pointed out that the PoC is unstable and may require repeated attempts, but when successful, it creates a DLL in System32 with full user permissions. The researcher also claims taking control of Kaspersky’s UI process can disrupt the antivirus and interfere with file-access controls, potentially leaving the system in an unstable state.

Nightmare Eclipse says the Kaspersky Endpoint Security zero-day allows privilege escalation on a fully patched Windows 11 25H2 system running Kaspersky Endpoint v14.0.0.504.

The researcher also released a zero-day exploit targeting GenDigital Avast Antivirus, named PrettyPrague. The exploit triggers a privilege escalation flaw.

The expert claims to have found another zero-day in an antimalware product, this time targeting Avast Antivirus. The PoC exploits a flaw in Avast Sandbox to dump the Windows SAM database and gain a SYSTEM-level shell. It reportedly works even on fully patched Avast Antivirus and Windows 11 25H2. The researcher also suspects the flaw may affect other Gen Digital products, including AVG and Norton.

Finally, Chaotic Eclipse released a new zero-day exploit targeting Crowdstrike Falcon cybersecurity platform. The researcher named the exploit FalconFlank, it triggers a privilege escalation flaw.

According to the researcher, FalconFlank abuses Falcon’s “Microsoft Office file malicious macro removal” feature. The function is part of Falcon’s remediation capabilities and operates with high privileges. The researcher claims that this behavior can be abused to escalate privileges from a low-privileged local user to a more powerful context.

Chaotic Eclipse is a researcher known for publicly releasing PoC exploits for zero-day vulnerabilities, often after criticizing vendors’ handling of vulnerability reports. His releases have mainly targeted Microsoft products, including Windows and Microsoft Defender, with some later exploited in the wild. Among the most notable are the Undefend and RedSun Defender zero-days.

His work has fueled debate over responsible disclosure and the risks of publishing working exploits.

Recently, Chaotic Eclipse revealed that he is Abdelhamid Naceri, a security researcher. Naceri previously worked with Microsoft in the UK and Germany. In a now-deleted X post, he described his departure from the company, claiming Microsoft terminated his employment without giving him a clear reason. He said Microsoft offered several financial settlements, but he rejected them because he wanted a formal explanation and help staying in Germany.

Naceri also said he challenged the dismissal in a German labor court. According to his account, Microsoft changed its arguments during the case, but the court ultimately upheld the termination. He said the long legal dispute left him with almost no compensation and caused serious financial and emotional problems, including treatment in a psychiatric hospital.

The researcher also admitted that an earlier claim that Microsoft had taken legal action against him was fabricated. The claim came during the controversy over Microsoft’s threats of legal action against security researchers who disclosed zero-day vulnerabilities.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, BigDiskBuster)







Source link