Published · 4d agoSecurity3 min read
Defender broke on a signature update, and the fix Microsoft offered was to roll forward
Admins reinstalled Windows after Defender scans began crashing with 0xc0000005 errors. The remedy was a newer signature build, which is not the same thing as a rollback.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Microsoft resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems.
- Reports on social media and "Threat service has stopped. Restart it now" error messages appeared on Windows 10 and Windows 11 devices starting Tuesday afternoon.
- The Defender failures prompted some affected customers to reinstall the operating system.
- A Windows system administrator said: "Beginning this morning, quick or full scans are failing, and will occasionally fail to the point where the Defender service needs to be restarted."
- The same administrator said they came across the problem while responding to a separate infection, initially attributed it to Defender being broken by the infection, and then recreated the issue on other devices simply by initiating a Quick Scan.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Microsoft has fixed a bug that made Windows Defender crash after a recent security update, throwing 0xc0000005 access violation errors on affected machines [1]. Before the fix landed, some customers reinstalled the operating system to get a working scanner back [3], which is a disproportionate remedy for a definition file and a useful measure of how little control administrators have over that channel.
The symptoms started on a Tuesday afternoon and showed up on both Windows 10 and Windows 11 as "Threat service has stopped. Restart it now" [2]. One Windows administrator described quick and full scans failing, occasionally badly enough that the Defender service had to be restarted [4]. The same administrator found the fault while responding to an unrelated infection, initially assumed Defender had been damaged by the malware, and then reproduced the crash on other devices simply by starting a Quick Scan [5]. That is the worst possible sequencing: the scanner fails during an active incident, and the responder spends time deciding whether the tool or the host is compromised.
Microsoft confirmed the issue to BleepingComputer and said it had been addressed in a new signature update [6]. A Microsoft spokesperson told BleepingComputer, "We have addressed this with a fix and recommend customers apply the latest update or enable automatic updates" [7]. The company said the fix applies automatically once Microsoft Defender Antivirus signature update version 1.457.236.0 or later is installed [8], and advised affected users to update through Windows Update and then verify they have the latest security intelligence update [9].
Read that guidance closely. The publicly offered path is forward only: install a newer build, or turn on automatic updates so a newer build arrives on its own [7][8]. Nothing in Microsoft's statement to BleepingComputer described pinning, staging, or reverting definitions [7][9]. Operators who would never let an OS patch reach every endpoint on the same afternoon are, by default, doing exactly that with the content that drives their scanner, several times a day, with no described way back.
This is the third Defender-side failure reported in this account inside roughly a year [12]. In May, administrators reported Defender flagging DigiCert root certificate entries as Trojan:Win32/Cerdigent.A!dha, producing widespread false positives and in some cases stripping certificates out of the Windows trust store [10]. In December 2025, a Defender portal outage blocked some Defender XDR capabilities and disrupted threat hunting alerts [11]. Different failure modes, one shared property: the blast radius is set by the vendor's release cadence, not by the customer's change window.
What to watch: whether Microsoft publishes any detail on how the bad signature build cleared testing, and whether it offers a supported way for enterprises to stage or roll back definition versions rather than only roll forward [7][8]. In the meantime, the operational question worth answering this week is a local one. If your scanner stops scanning at 2pm, how long before someone notices, and what is the documented step after "restart the service"? For at least some customers here, the answer was reinstalling Windows [3].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems.
ReportedView cited source - [2]
Reports on social media and "Threat service has stopped. Restart it now" error messages appeared on Windows 10 and Windows 11 devices starting Tuesday afternoon.
ReportedView cited source - [3]
The Defender failures prompted some affected customers to reinstall the operating system.
ReportedView cited source - [4]
A Windows system administrator said: "Beginning this morning, quick or full scans are failing, and will occasionally fail to the point where the Defender service needs to be restarted."
- [5]
The same administrator said they came across the problem while responding to a separate infection, initially attributed it to Defender being broken by the infection, and then recreated the issue on other devices simply by initiating a Quick Scan.
- [6]
Microsoft confirmed the issue and told BleepingComputer that the bug has been addressed in a new signature update.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comSergiu Gatlan4d agoMicrosoft fixes known issue causing Windows Defender crashes
- scworld.comSC Staff3d agoMicrosoft Defender bug causing crashes resolved
Additional citations
- unnamed Windows system administrator quoted by BleepingComputer
- Microsoft, to BleepingComputer
- Microsoft spokesperson, to BleepingComputer



