A security update Microsoft released this week to address a zero-day flaw in Windows Defender could allow attackers to fill a computer's hard drive with data. The issue was identified by the researcher who originally disclosed the vulnerability.
Microsoft issued the patch on Wednesday for a flaw tracked as CVE-2026-50656. The update targets the Microsoft Malware Protection Engine used by Defender and installs automatically on affected systems.
Researcher NightmareEclipse reported on Thursday that the added protections can cause the mpengine.dll file to leak data. This occurs when the engine processes certain files through the SpyNet cloud service, bypassing normal size limits on quarantined content.
The researcher described a method using a custom SMB server to trigger the behavior. A malicious file paired with an oversized Zone.Identifier stream can lead Defender to hang while locking large amounts of disk space.
Microsoft has not yet confirmed the reported side effect. The disclosure continues an ongoing dispute between the researcher and the company that began earlier this year.