Windows Defender Crashed Mid-Scan After Buggy Update, Microsoft Ships Fix

A faulty signature update knocked out Microsoft's built-in antivirus on Windows 10 and 11 machines this week, leaving scans failing and some users reinstalling their operating system before a patch arrived.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9, a cracked glass surface with two distinct reflections distorted and fragmented, cold blue and steel grey tones, harsh over
Share

Key points

  • Microsoft confirmed a bug in a recent Windows Defender signature update that caused the antivirus to crash with a 0xc0000005 error during quick or full scans.
  • Affected users saw a "Threat service has stopped. Restart it now" message on Windows 10 and Windows 11 machines starting Tuesday afternoon.
  • The fix ships in Microsoft Defender Antivirus signature update version 1.457.236.0 or later, applied automatically to systems with updates enabled.
  • Some users reinstalled Windows before the fix landed, believing their machines were infected.
  • This follows a May incident where Defender wrongly flagged DigiCert root certificates as malware, and a December 2025 outage of the Defender XDR portal.

Microsoft has patched a bug that was crashing Windows Defender, the free antivirus built into Windows, whenever users tried to run a scan.

The problem started on Tuesday afternoon. Windows 10 and Windows 11 users began seeing an error message that read "Threat service has stopped. Restart it now." Behind the scenes, the antivirus was hitting a 0xc0000005 access violation, which is Windows shorthand for a program trying to touch memory it is not allowed to touch.

Quick scans failed. Full scans failed. In some cases the whole Defender service had to be restarted to come back to life.

What actually broke?

A recent signature update, meaning the small daily file Defender downloads to recognise new viruses, contained a bug that made the scanning engine crash. It was not a virus. It was Microsoft's own update tripping up Microsoft's own antivirus.

One Windows administrator, writing on Microsoft's support forum, said they first noticed it while cleaning up a separate malware infection and assumed the real virus had damaged Defender. Then they reproduced the crash on clean machines just by starting a quick scan.

That is how widespread it was. Any Windows PC running the bad signature file and asked to scan itself would fall over.

Should ordinary users do anything?

Most people do not need to lift a finger. Microsoft told BleepingComputer, which first reported the fix, that the patched signature update is already going out through Windows Update and will install automatically on machines with automatic updates turned on.

If you want to check manually, open Windows Update and look for the latest security intelligence update. The bug is fixed in Microsoft Defender Antivirus signature update version 1.457.236.0 or later.

A Microsoft spokesperson said: "We have addressed this with a fix and recommend customers apply the latest update or enable automatic updates."

Did anyone lose data?

No data loss has been reported, but some users took drastic action before Microsoft acknowledged the problem. Posts on social media and Microsoft's own support site show people reinstalling Windows from scratch, convinced the crashing antivirus meant their PC was infected.

It was not. It was a bad update.

A rough year for Defender

This is the third Defender wobble in roughly six months.

Date Issue Impact
December 2025 Defender XDR portal outage Blocked threat hunting features for business users
May 2026 False positive on DigiCert root certificates Flagged legitimate certificates as Trojan:Win32/Cerdigent.A!dha, removed some from Windows
This week Signature update crash Quick and full scans failed with 0xc0000005 errors

The DigiCert incident in May was arguably worse for businesses. Defender wrongly identified trusted certificate entries as malware and, in some cases, deleted them from the Windows certificate store, which is the list of authorities your PC trusts to verify secure websites and software signatures.

Security software crashing is annoying. Security software deleting the wrong files is dangerous. Both come down to the same thing: an update that was not tested thoroughly enough before it reached hundreds of millions of machines.

For now, the immediate crash is fixed. Turn on automatic updates if you have not already, run Windows Update, and let Defender get on with its job.

© 2026 Threat Vectr