Skip to main content
CybersecurityVulnerability Management

Microsoft Fixes Bug Disrupting Windows Defender Scans

Windows Defender error message on laptop screen in cluttered home office setting.

"Beginning this morning, quick or full scans are failing, and will occasionally fail to the point where the Defender service needs to be restarted," one Windows system admin said.

Windows Defender crashes and 0xc0000005 access violation errors

Microsoft has resolved a bug that caused Windows Defender to crash on some machines, producing 0xc0000005 access violation errors. The failures surfaced on Windows 10 and Windows 11 devices, with affected users seeing messages such as "Threat service has stopped. Restart it now." In some cases the crash behavior was disruptive enough that customers chose to reinstall the operating system.

Customer reports: quick scans, recreation, and social media chatter

Reports emerged on social media and from at least one administrator who encountered the failure while responding to an unrelated infection. That administrator said they were initially confident the infection had "borked" Defender, only to recreate the behavior on other devices simply by initiating a Quick Scan. Other technicians reported that quick or full scans were failing intermittently, sometimes to the point where the Defender service required a restart.

Microsoft's fix: signature update 1.457.236.0 and automatic remediation

Microsoft confirmed the problem and told BleepingComputer that the bug "has been addressed in a new signature update." A Microsoft spokesperson said, "We have addressed this with a fix and recommend customers apply the latest update or enable automatic updates." The company added that the fix will be applied automatically after installing Microsoft Defender Antivirus signature update version 1.457.236.0 or later. Affected users are advised to update their systems via Windows Update and then check whether they have the latest security intelligence update installed.

Related Microsoft Defender incidents: DigiCert certificate flags and a portal outage

The Defender crash is the latest in a series of operational incidents recorded in recent months. In May, system administrators reported that Microsoft Defender flagged DigiCert root certificate entries as Trojan:Win32/Cerdigent.A!dha, producing widespread false-positive alerts and, in some cases, removing certificates from the Windows trust store. Months earlier, in December 2025, a widespread Microsoft Defender portal outage blocked access to some Defender XDR portal capabilities and disrupted threat hunting alerts. Those prior episodes underscore a pattern of availability and accuracy problems that can complicate enterprise response and trust in defensive tooling.

How system administrators, affected customers, and security teams should respond

  • System administrators: Apply updates via Windows Update and verify Microsoft Defender Antivirus signature update version 1.457.236.0 or later is installed. Where automatic updates are available, enable them as recommended by Microsoft to receive the fix without manual intervention.
  • Affected customers: If you saw "Threat service has stopped. Restart it now" messages or repeated scan failures, install the security intelligence update and confirm scans run normally before taking extreme remediation steps such as reinstalling the OS.
  • Security teams: Track both accuracy and availability metrics for Defender components. Prior incidents — the May DigiCert false positives and the December 2025 portal outage — show that alerts can be both false and disruptive. Teams should validate that threat-hunting and detection pipelines resumed normal operation after this fix and note any downstream effects from interrupted scans.

The immediate technical remedy is narrow and explicit: install the Microsoft Defender Antivirus signature update version 1.457.236.0 or later, or enable automatic updates so the patch is applied automatically. Microsoft has confirmed the fix and directed customers to apply the latest update; administrators who experienced scan failures or service restarts should verify the update and confirm that scans complete successfully. The sequence of recent incidents — false-positive certificate flags, a portal outage, and now a signature-triggered crash — leaves a clear, pragmatic next step for operators: validate updates and monitor whether scanning and portal capabilities return to normal.

Original BleepingComputer story