Is the Microsoft Defender fix worse than the problem? The patch on Windows fills the disk

Written by Jason Miller

Microsoft has released an update for Windows Defender that, while fixing a critical zero-day vulnerability, could trigger a new, perhaps even worse problem: therunning out of disk space. The researcher who first discovered the flaw, known by the pseudonym NightmareEclipse, has in fact reported that the implemented patch has a serious side effect.

The original vulnerability, identified as CVE-2026-50656 and known as RoguePlanetsurfaced in June when NightmareEclipse made it public, including the code to exploit it. This flaw allowed remote attackers to gain administrative control over Windows 10 and Windows 11 systems, even with Defender real-time protection disabled. In recent months, the same researcher has disclosed several other zero-day vulnerabilities, forcing Microsoft to take quick action to release fixes.

The “defense in depth” that risks blocking the system

The Redmond giant announced on Wednesday that it had resolved RoguePlanet with an update to Microsoft Malware Protection Enginethe heart of the Defender antivirus application. The fix is ​​downloaded and installed automatically, without requiring user intervention. The update also includes “defense-in-depth updates aimed at improving security features.”

However, NightmareEclipse revealed that these very “defense in depth” additions create behavior that could allow attackers to completely saturate the available space on a hard drive, writing massive amounts of data. The new mitigations introduced a problem in the driver mpengine.dllassociated with the Microsoft Malware Protection Engine, which in some cases causes a loss of 8 bytes of data every time it tries to open a file. Also new features in SpyNeta cloud service that allows Microsoft Security Essentials or Forefront Endpoint Protection to send reports to Microsoft about suspicious software, contribute to this potential bulk file writing behavior.

Normally, Defender imposes strict limits on the size of files that can be written to disk during scanning and quarantine, to prevent an excessively large file from running out of available space.

The researcher explained that “this implementation makes sense, because quarantining a huge file would cause Defender to completely run out of available disk space.” However, he identified one specific exception to this rule: “Apparently the spynet functions in mpengine.dll want to keep a local copy of the file ADS Zone.Identifier and no matter how large this file is, Windows Defender will still cache it locally”. It is precisely this anomalous interaction, in combination with data loss, that opens the door to risk of disk saturation.

Jason Miller

I'm Jason Miller, and I've been passionate about technology and storytelling for over a decade. As a lead writer at Herald Editorials, I strive to bring clarity and creativity to complex tech topics. When I'm not writing, you'll find me exploring the latest gadgets or hiking in the great outdoors.