Updates

Microsoft Defender Crash Troubles Users After Faulty Security Update

4 min read Editorial
  • Status: Confirmed / Under Investigation
  • Affected Components: Microsoft Defender Antivirus v1.1.26070.7 and v1.1.26080.2 paired with Microsoft Security Intelligence Update versions 1.457.222.0, 1.457.225.0, 1.457.226.0, 1.457.227.0, and 1.457.230.0
  • Reported Symptoms: Full scans and Quick scans crash a few seconds into execution; offline scans halt at approximately 90% to 93% completion
  • Workaround: Right-click a specific folder or drive and select Scan with Microsoft Defender

If you have been trying to run a routine antivirus check on your Windows machine only to watch Microsoft Defender crash just seconds after it starts, you are not alone. The issue was first flagged on Reddit by user Huynh_Jovi, and a growing thread of affected users has since confirmed that both Full and Quick scans are failing. According to the Windows Insider community and cross-referenced reports, the problem appears directly tied to a recently deployed Microsoft Security Intelligence update. Until Microsoft issues an official statement, the community has pinpointed the exact version causing the breakdown and identified a working upgrade path to restore protection.

How the Crash Manifests

Users reporting the problem describe a consistent pattern. You open the Windows Security app, initiate a Quick scan, and the progress bar ticks forward for a handful of seconds before the interface freezes and the scan window closes. Full scans behave the same way, though they tend to run a bit longer before terminating. Several users have also noted that offline scans, which typically run before Windows boots, stop precisely between 90% and 93% of completion. The latest version of the standalone Microsoft Safety Scanner is reportedly experiencing the same failure mode.

A stylized system scan progress bar stuck at ninety percent, glowing soft blue against a dark UI theme, with a subtle pa
Offline scans are reportedly halting between ninety and ninety-three percent completion.

Why the Microsoft Defender Crash Is Happening

While Microsoft has not yet published an official advisory, community analysis strongly points to a specific Microsoft Security Intelligence update as the culprit. These intelligence updates are routine downloads that refresh Defender malware signature database, allowing it to recognize newly discovered threats. The problematic versions appear to be 1.457.222.0, 1.457.225.0, 1.457.226.0, 1.457.227.0, and 1.457.230.0, but only when paired with Defender Antivirus versions v1.1.26070.7 or v1.1.26080.2.

Advertisement

The timing of the rollout adds another layer to the investigation. Security researchers recently disclosed ShieldBreak, a zero-day vulnerability that was patched during August Patch Tuesday. It is highly plausible that Microsoft attempted to deploy a rapid mitigation or signature adjustment to counter the newly exploited flaw, and that accelerated package introduced a conflict in Defender scanning engine. Restoring an older, pre-broken Security Intelligence update also resolves the crash, which heavily supports the theory that a specific signature bundle is destabilizing the antivirus process.

How to Get the Fix

Fortunately, you do not need to manually hunt down a corrected package. Community reports confirm that upgrading to Microsoft Security Intelligence Update v1.457.236.0 resolves the scanning crash entirely. To trigger the update, open Windows Update from the Settings app and click Check for updates. Alternatively, navigate to Windows Security > Virus & threat protection > Virus & threat protection updates > Check for updates. If the newer intelligence version is available through your configured update channel, it should download and install automatically within a few minutes.

A modern desktop interface showing the Windows Security settings panel with a magnifying glass icon, rendered in a clean
Checking for updates through Windows Security should push the corrected intelligence package.

What This Means for You

Until the corrected intelligence update rolls out to your device, your system is not entirely defenseless, but your ability to manually verify its health is severely limited. Background real-time protection should continue running, meaning active threats will still be blocked as they try to execute. However, if malware manages to bypass real-time detection, you will not be able to run a full system sweep to locate it. That gap is exactly why the manual scan workaround exists.

If you suspect your machine has been compromised or simply want to verify that Defender is functioning normally, right-click the folder or drive you want to check and select Scan with Microsoft Defender from the context menu. This bypasses the main Windows Security app interface and has been reported to complete successfully for users stuck on the broken update versions. It is worth noting that this is a targeted scan, not a full system sweep, so it will not catch threats hiding in system directories or startup items.

IT administrators managing enterprise fleets should monitor Windows Update for Business or your WSUS and Intune deployment rings for the v1.457.236.0 intelligence update. Delaying deployment until the fix is confirmed in your staging environment will prevent widespread scanning failures across your managed devices. Microsoft typically addresses signature-related regressions quickly, but the gap between the initial rollout and the corrective push could leave some systems in a partially blind state for several days.

Source: Latest from Windows Central

Over to you: Are you currently seeing Defender crash on your machine, or has the v1.457.236.0 patch already restored your scans?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement