Skip to content
Hi-Tech, Technology

Windows Defender update breaks scanning after fixing the ShieldBreak vulnerability.

AuthorEditorial team 20-08-2026, 04:36 101
Windows Defender update breaks scanning after fixing the ShieldBreak vulnerability.
Advertising
In brief
  • ShieldBreak allowed obtaining SYSTEM privileges in Windows.
  • After the patch, Defender does not perform quick and full scans.
  • Rolling back to the previous version resolves the issue.

At the beginning of this month, a zero-day vulnerability named ShieldBreak was discovered in the Windows Defender antivirus module. Exploiting this vulnerability allowed attackers to gain SYSTEM-level privileges on Windows 10, Windows 11, and Windows Server systems, enabling them to fully control the infected computer.

Microsoft promptly released a security update aimed at closing the vulnerability. The patch was distributed through Windows Update and Microsoft Security Intelligence Update, and was initially perceived as a solution to a critical issue.

However, just a few days after the update was installed, users began reporting malfunctions in Defender itself. Quick scans and full scans were ending with errors, while the offline scanner was freezing at the 91% mark. Meanwhile, manual scanning of the entire disk, initiated through the interface, continued to work, indicating a specific failure in processing certain scanning modes.

Technical details of the failure

Errors with code 0x000005 are recorded in the Windows event log, indicating the library mpengine.dll – a key component of the antivirus engine. There are also reports of session failures DefenderApiLoggerLowPriv. According to Neowin forum leader and former ESET researcher Arye Goretsky, the issue affects Defender versions v1.1.26070.7 and v1.1.26080.2, working in conjunction with certain versions of Microsoft Security Intelligence Update.

Microsoft has not officially confirmed that the latest patch caused the failures, however, users note that rolling back the system to previous versions of Defender completely resolves the issue. This indirectly confirms a link between the update and the scanning disruption.

The failure of scanners is particularly felt by corporate clients and organizations where Windows Defender is often used as the primary protection against malware. The loss of the ability to quickly scan the system complicates the response to new threats, and the freezing of the offline scanner makes it impossible to check without a network connection.

Experts recommend temporarily disabling automatic scans until the issue is fully resolved and using alternative antivirus solutions for critical servers. Additionally, it is advised to regularly create restore points and back up important data.

The situation highlights the importance of thorough testing of updates, especially in environments where malware protection plays a key role. Despite Microsoft's quick response in the form of a patch, the resulting side effect shows that even large vendors can face unforeseen consequences when fixing vulnerabilities.

Users facing issues can revert to previous versions of Defender by rolling back updates or using system recovery tools. A corrective update is expected to be released by Microsoft in the coming weeks to resolve the conflict between the new protection engine and scanning mechanisms.

Source: 3DNews

How useful is the material?Evaluation helps us choose topics
00 ratings
Analytics

Story statistics

101views
0comments
2min read
149 / 218rank among section stories

Discussion

No one has spoken yet — be the first.

Comments are written by participants Log in to the site — it's free and takes a minute. Comments are moderated.
Log in
Advertising

What searches this page answers