Windows Defender patch may enable disk space exhaustion

A security update Microsoft released this week to address a zero-day flaw in Windows Defender could allow attackers to fill a computer's hard drive with data. The issue was identified by the researcher who originally disclosed the vulnerability.

Microsoft issued the patch on Wednesday for a flaw tracked as CVE-2026-50656. The update targets the Microsoft Malware Protection Engine used by Defender and installs automatically on affected systems.

Researcher NightmareEclipse reported on Thursday that the added protections can cause the mpengine.dll file to leak data. This occurs when the engine processes certain files through the SpyNet cloud service, bypassing normal size limits on quarantined content.

The researcher described a method using a custom SMB server to trigger the behavior. A malicious file paired with an oversized Zone.Identifier stream can lead Defender to hang while locking large amounts of disk space.

Microsoft has not yet confirmed the reported side effect. The disclosure continues an ongoing dispute between the researcher and the company that began earlier this year.

Verwandte Artikel

A newly published zero-day exploit allows attackers with physical access to bypass BitLocker encryption on Windows 11 devices in seconds. The attack, named YellowKey, targets the default TPM-only configuration and grants full access to encrypted drives via a simple USB-based method.

Von KI berichtet

Daemon Tools, a popular disk image mounting app, was compromised in a supply-chain attack starting April 8, delivering malware through official updates. Security firm Kaspersky reported infections on thousands of machines across over 100 countries. Users are urged to scan their systems immediately.

A ransomware group known as ShinyHunters exploited a critical zero-day flaw in Oracle’s PeopleSoft software to target about 100 organizations. The attackers stole gigabytes of data from victims, including the University of Nottingham, and issued extortion demands. Oracle has released a mitigation but not a full patch.

Von KI berichtet

Google published proof-of-concept exploit code on Wednesday for a vulnerability in its Chromium browser that has gone unfixed for 29 months. The flaw affects Chrome, Microsoft Edge, and other Chromium-based browsers used by millions worldwide. It enables attackers to establish persistent connections for monitoring user activity and launching attacks.

Diese Website verwendet Cookies

Wir verwenden Cookies für Analysen, um unsere Website zu verbessern. Lesen Sie unsere Datenschutzrichtlinie für weitere Informationen.
Ablehnen