Windows users are reporting that a Windows Defender scan bug has returned in a major way, with antivirus protection grinding to a halt across multiple scan types. According to widespread user reports tracked by Neowin, quick scans, full system scans, and even offline malware scans are now failing to complete after Microsoft rolled out a defensive update intended to close a 0-day vulnerability.
Windows Defender Scan Bug: What Is Actually Breaking?
If you recently opened the Windows Security app and tried to run a scan, you likely noticed the progress bar stall or the operation simply terminate without a result. Multiple users have confirmed that the issue is not isolated to a single scan type. Quick scans, which normally check high-risk directories and active processes, are hanging. Full scans, which walk through every file on your drives, are aborting mid-operation. Even the offline scan, which runs before Windows loads to catch persistent threats, is failing to launch properly.
The pattern points to a core component failure rather than a corrupted definition file. When Defender definitions update, individual scan types usually still function, even if the database is outdated. When the scanning engine itself stops processing, it typically means a service dependency or a core DLL has been altered by the update.
Why the 0-Day Patch Backfired
Microsoft’s Security Response Center routinely pushes out emergency patches when a 0-day flaw is actively exploited in the wild. These updates are designed to close a specific attack vector, but they often touch the same system libraries that built-in components rely on. In this case, the patch appears to have modified a component that Windows Defender depends on to initialize its scanning routines.
Defender’s real-time protection and on-demand scanning both hook into the Windows Filtering Platform and kernel-mode callback system. If a patch changes how those callbacks register or how the security service starts, the entire scanning pipeline can break. Microsoft has not yet published a detailed root cause analysis, but the timing strongly suggests the 0-day mitigation disrupted Defender’s initialization sequence.

What This Means for You
Real-time protection is still active. Microsoft has confirmed that the background monitoring service continues to run, meaning your system is not completely exposed. However, the inability to manually trigger scans removes a critical troubleshooting tool. If you download a suspicious file or want to verify your system after a browser session, you will not get a clean report from Defender until the issue is resolved.
For most home users, this is a temporary setback. The patch that closed the 0-day flaw remains in place, and Microsoft will likely push a corrective update once engineers identify the exact dependency that broke. Enterprise administrators should monitor patch compliance closely and prepare to roll back the offending update if scanning failures impact your security baseline requirements.
What to Do Right Now
Do not uninstall the recent security update. Rolling back the 0-day patch leaves you exposed to the original vulnerability, which is the exact flaw you just tried to close. Instead, rely on the built-in Windows Security dashboard for ongoing protection, and avoid opening untrusted files until Microsoft confirms a fix.
If you need to verify your system immediately, consider using a reputable second-opinion scanner from a removable drive. Tools like the Microsoft Safety Scanner can run without depending on the broken Defender service. Keep an eye on the Windows Update history, and when Microsoft publishes a follow-up patch or a support article addressing this specific issue, apply it promptly.

Microsoft typically acknowledges these types of regression bugs within a few days and rolls out a hotfix through the monthly Patch Tuesday cycle or an out-of-band update. Until then, your system remains protected by real-time monitoring, even if manual scans are offline. We will update this article as soon as the company provides an official status update on the fix timeline.
Source: Neowin
Over to you: Are you relying on Windows Defender for now, or switching to a third-party antivirus until Microsoft rolls out the fix?



