Windows Defender Crashed Mid-Scan After Buggy Update, Microsoft Ships Fix

A faulty signature update knocked out Microsoft's built-in antivirus on Windows 10 and 11 machines this week, leaving scans failing and some users reinstalling their operating system before a patch arrived.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A Windows desktop screen frozen mid-antivirus scan with a crash dialog box visible, surrounded by frustrated user workspaces in the background, with error messa
Share

Key points

  • Microsoft confirmed a bug in a recent Windows Defender signature update that caused the antivirus to crash with a 0xc0000005 error during quick or full scans.
  • Affected users saw a "Threat service has stopped. Restart it now" message on Windows 10 and Windows 11 machines starting Tuesday afternoon.
  • The fix is in Microsoft Defender Antivirus signature update version 1.457.236.0 or later, applied automatically to systems with updates enabled.
  • Some users reinstalled Windows before the fix landed, believing their machines were infected.
  • This follows a May incident where Defender wrongly flagged DigiCert root certificates as malware, and a December 2025 outage of the Defender XDR portal.

Microsoft has patched a bug that was crashing Windows Defender, the free antivirus built into Windows, whenever users tried to run a scan.

The problem started Tuesday afternoon. Windows 10 and Windows 11 users began seeing the message "Threat service has stopped. Restart it now." Behind the scenes, the antivirus was hitting a 0xc0000005 access violation, Windows shorthand for a program trying to read memory it isn't allowed to touch. Quick scans failed. Full scans failed. In some cases the Defender service had to be restarted before it would come back at all.

What actually broke?

A recent signature update, the small daily file Defender downloads to recognise new threats, contained a bug that made the scanning engine crash. It wasn't a virus. Microsoft's own update tripped up Microsoft's own antivirus.

One Windows administrator, writing on Microsoft's support forum, said they first noticed it while cleaning up a separate malware infection and assumed that infection had damaged Defender. Then they reproduced the crash on clean machines simply by starting a quick scan. Any Windows PC running the bad signature file would fall over the moment it tried to scan itself.

Should ordinary users do anything?

Most people don't need to lift a finger. Microsoft told BleepingComputer, which first reported the fix, that the patched signature is already rolling out through Windows Update and installs automatically on machines with automatic updates enabled.

To check manually, open Windows Update and pull the latest security intelligence update. The bug is resolved in signature version 1.457.236.0 or later. A Microsoft spokesperson told BleepingComputer: "We have addressed this with a fix and recommend customers apply the latest update or enable automatic updates."

Did anyone lose data?

No data loss has been reported, but some users took drastic action before Microsoft acknowledged the problem. Posts on social media and Microsoft's own support site show people reinstalling Windows from scratch, convinced a crashing antivirus meant infection. It didn't.

A rough year for Defender

We've tracked Microsoft Defender closely since May 2026, and this week's crash is the third reliability stumble in roughly six months.

Date Issue Impact
December 2025 Defender XDR portal outage Blocked threat hunting features for business users
May 2026 False positive on DigiCert root certificates Flagged legitimate certificates as Trojan:Win32/Cerdigent.A!dha, removed some from Windows
This week Signature update crash Quick and full scans failed with 0xc0000005 errors

The DigiCert episode in May was arguably worse for businesses. Defender wrongly identified trusted certificate entries as malware and, in some cases, deleted them from the Windows certificate store, the list of authorities a PC trusts to verify secure websites and software signatures. Crashing is annoying. Deleting the wrong files is dangerous. Both failures trace back to the same root cause: an update that wasn't tested thoroughly enough before it reached hundreds of millions of machines.

For anyone still running Windows 10, it's worth noting that Microsoft's August 2026 security patch is also waiting if you haven't applied it. Enable automatic updates, let Defender fetch the fixed signature, and move on.

© 2026 Threat Vectr