Windows Defender Update for Critical 0-Day CVE-2023-XXXX Breaks Virus Scans
Key Takeaways Microsoft Defender experienced widespread scan failures across Quick, Full, and Offline modes following security intelligence updates on August 18, 2026. The issue affects both home...
Key Takeaways
- Microsoft Defender experienced widespread scan failures across Quick, Full, and Offline modes following security intelligence updates on August 18, 2026.
- The issue affects both home users and enterprise environments utilizing Defender for Endpoint, leaving systems without reliable malware scanning capabilities.
- The crashes are linked to specific versions of the Microsoft Malware Protection Engine and Security Intelligence Updates, resulting in an access violation (0xC0000005) within MsMpEng.exe.
- While Microsoft investigates, a potential fix involves updating to Security Intelligence Update 1.457.236.0 or later, though some users may require even newer versions.
- The timing of the incident has led to speculation that the update was a hurried response to a recently disclosed Windows Defender zero-day vulnerability, “ShieldBreak,” though Microsoft has not confirmed this connection.
Microsoft Defender, the built-in antivirus solution for Windows, has been experiencing critical failures in its virus scanning functions since a series of Security Intelligence updates began rolling out on August 18, 2026. This disruption has left both individual users and administrators of Defender for Endpoint without the ability to perform crucial malware checks.
Table Of Content
The anomaly, which community members are largely attributing to a faulty definition update, has prompted some Reddit users to speculate a more urgent cause: a rapid response to “ShieldBreak,” a recently published zero-day exploit targeting Defender. ShieldBreak emerged after Microsoft’s August 2026 Patch Tuesday, raising questions about the timing of the Defender update.
Widespread Scan Failures Reported
Reports from various platforms, including Neowin, CyberInsider, Reddit, and Microsoft Q&A, consistently describe the same problematic behavior. When users attempt to initiate a Quick or Full scan, Windows Security reports that the threat service has stopped and prompts a restart. Subsequent attempts to restart the service or run another scan do not resolve the issue, with the scan failing to complete.
Offline scans are also affected, typically freezing between 90% and 93% completion. Even the Microsoft Safety Scanner, usually a reliable alternative when Defender encounters issues, is reportedly exhibiting the same malfunction, severely limiting users’ options for malware detection. Interestingly, some users have noted that manual scans of entire drives can still finish, suggesting the problem might be localized to Defender’s scheduled scan pathways rather than every file inspection process.
Event logs shared by users, including Nevvaren, Leather_Squirrel_477, and Xander Warren on Microsoft Q&A, pinpoint the antimalware process MsMpEng.exe as the culprit, crashing within mpengine.dll with an access violation exception code 0xC0000005.
Former ESET researcher and Neowin forum supervisor Aryeh Goretsky identified the pattern as affecting Microsoft Malware Protection Engine versions 1.1.26070.7 and 1.1.26080.2 when combined with Security Intelligence Update versions 1.457.222.0, 1.457.225.0, 1.457.226.0, 1.457.227.0, and 1.457.230.0. Later community observations also included version 1.457.235.0. The identical crash behavior on both fresh Windows installations and managed enterprise endpoints has led administrators to reassure users that a failed scan, by itself, does not necessarily indicate an infection.
The Shadow of ShieldBreak
The timing of these Defender issues has fueled speculation. Just days after the August Patch Tuesday, researcher Nightmare Eclipse publicly released “ShieldBreak,” a proof-of-concept for a local privilege escalation vulnerability targeting Defender. This exploit was described as a bypass for a previous bug, CVE-2026-50656, also known as RoguePlanet.
Reddit users Taiwendo and blondacuaripi have openly theorized that the scan failures could be unintended consequences of a rushed signature or engine update designed to mitigate the ShieldBreak zero-day. While Microsoft has not corroborated any direct link, and subsequent analyses have cautioned against equating correlation with causation, ShieldBreak remains a significant vulnerability in its own right.
Independent researchers have verified that the ShieldBreak exploit can successfully elevate a low-privileged user to SYSTEM-level access, even when Defender is active. Microsoft has confirmed it is investigating the reports related to ShieldBreak but had not issued an official incident bulletin regarding the scan failures at the time of this report.
Potential Resolution and Mitigation
According to Goretsky and Reddit users such as Schoonie84 and Master_Pie1940, updating to Security Intelligence Update 1.457.236.0 via Windows Update has reportedly restored scan functionality for many affected systems. However, testing on August 19 revealed that this particular build was not universally effective, with some PCs requiring version 1.457.238.0 or even newer packages before Quick Scans would complete successfully. The key indicator of resolution is a completed scan after applying the latest available protection update, rather than relying solely on a specific version number from early forum discussions.
NovelExplorer suggested that if updating proves impossible, a System Restore to August 16 could be a temporary workaround, though this would also revert any malware definitions to an earlier state.
What You Should Do
- Update Defender Immediately: Ensure your Windows Defender Security Intelligence is updated to the latest available version (1.457.236.0 or higher). Check Windows Update repeatedly until a scan completes successfully.
- Verify Scan Completion: After updating, run a Quick Scan and confirm that it completes without errors. Do not assume the issue is resolved until a scan finishes successfully.
- Use a Second-Opinion Scanner: If Defender scans continue to fail, utilize a trusted, reputable second-opinion antivirus scanner (e.g., from Malwarebytes, ESET, or another vendor) to check for potential threats until Defender is fully functional.
- Investigate Suspicious Files Separately: If a file or activity prompted your scan attempt, treat that as a separate security concern. Do not assume the Defender crash means your machine is clean.
- Consider System Restore (Last Resort): If all updating efforts fail, a System Restore to a point before August 18, 2026, could temporarily restore scan functionality, but be aware this will roll back security definitions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.