A newer Microsoft Defender Antivirus security intelligence update appears to have restored scanning on some Windows 10 and Windows 11 PCs after reports of Quick Scan and Full Scan failures, threat-service restart prompts and 0xc0000005 access-violation crashes. The apparent fix arrived through Defender’s own update channel rather than a full Windows patch, although Microsoft had not published a detailed public incident record confirming the precise cause or scope.
That’s welcome news for anyone who saw a Quick Scan or Full Scan fail, a “Threat service has stopped” prompt, or an application crash with the 0xc0000005 access-violation code. It also underlines a point that is easy to miss: endpoint protection isn’t a static Windows feature. Its content, scanning engine, platform binaries and update paths all change independently.
In brief: Reports on 18 and 19 August 2026 described Microsoft Defender Antivirus scans crashing on some Windows 10 and Windows 11 PCs. Users and administrators reported that security intelligence version 1.457.236.0 or later restored scanning. However, Microsoft had not, at publication, issued a detailed public incident notice confirming the precise trigger, affected Windows builds, editions or rollout scope. Treat that version as a practical recovery marker, not a complete root-cause report.
Multiple times per day
Microsoft says Defender security intelligence updates are delivered several times daily, while engine and platform updates follow a monthly cadence. That speed matters against new threats, but it also means a bad content change can surface quickly.
The fix looks credible. The formal incident record is thin.
The symptoms were consistent enough to suggest this wasn’t simply a damaged PC. Community reports described scans stopping, the Defender threat-protection service restarting or remaining unavailable, and 0xc0000005 errors after recent definition updates. BleepingComputer reported that Microsoft had resolved the known issue, while reports from affected users converged on a newer security intelligence package as the practical fix.
But the public evidence remains incomplete. There is no detailed Microsoft security-health entry publicly establishing that every Windows 10 or Windows 11 edition was affected, nor a definitive list of OS builds, Defender engine versions or file-scanning conditions that triggered the crash. Reports associate the issue with scans and Defender service availability. They don’t prove that every 0xc0000005 event on a Windows PC has the same cause.
That is not just editorial hedging. An access violation after an update can point to a vendor defect, but malware interference, damaged system components, incompatible endpoint agents and a competing antivirus product can also alter Defender’s behaviour. Microsoft notes that third-party antivirus products registered with Windows Security can disable Microsoft Defender Antivirus. In that state, its services and updates should not be expected to behave as though Defender were the active protection product.
Why an intelligence update can fix more than a signature
“Definitions” remains useful shorthand, but it understates what security intelligence does. It includes the threat-identification data and detection logic Defender uses when scanning files or observing activity. Microsoft delivers these packages frequently because malware, malicious infrastructure and unwanted software change quickly.
The update architecture is deliberately separate from the antivirus engine and platform:
- Security intelligence updates provide current threat knowledge and detection logic. Microsoft says they are delivered multiple times per day.
- Engine updates update the scanning engine that interprets and applies that intelligence.
- Platform updates update Defender’s program components, including the executable, DLL and driver files underpinning the service.
- Windows cumulative updates are wider operating-system servicing packages. They can include security and reliability changes, but they are not the only route through which Defender changes.
So checking Windows Update for a monthly cumulative patch isn’t always enough when Defender is misbehaving. The relevant remedy may arrive as KB2267602, the familiar label used for Defender security intelligence updates, and may appear in Windows Security’s protection-update page before any new OS build is deployed.
Microsoft’s documentation makes the split clear: platform and engine releases are normally monthly, while security intelligence updates are much more frequent. It also supports delivery through Microsoft Update, WSUS, Configuration Manager, a network share and the standalone security-intelligence download channel. Useful flexibility, but it means devices can receive the same corrective update at different times.
What to check before reinstalling Windows
For a home PC, start with the obvious checks. Open Windows Security, go to Virus & threat protection, and see whether the protection status reports a problem. Then open Protection updates and select Check for updates. Microsoft documents this as the standard route for manually requesting the latest security intelligence.
After updating, restart Windows once if Defender has stopped or repeatedly requested a restart, then run a Quick Scan. A Full Scan is a reasonable follow-up if the machine was affected. There is no value in repeatedly launching scans while the service is crashing.
Administrators need more than the familiar green Windows Security tick. In an elevated PowerShell session, Get-MpComputerStatus exposes the useful fields: AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, the signature version and the signature update time. Microsoft documents the cmdlet as the supported way to retrieve Defender’s antimalware status. It is a better starting point than reading a tray icon or drawing conclusions from one failed scan.
On a managed endpoint, establish where updates come from. A PC using WSUS or Configuration Manager may not receive the remedial package until it has been synchronised and approved. A device configured to use a file share may simply be consuming stale content. Microsoft specifically advises checking approval of Defender security intelligence updates in WSUS when manual updating works but normal updating does not.
Don’t start by changing Defender service start types in the registry or reinstalling Windows. A one-off reboot and a normal service-status check are reasonable; manual service surgery isn’t. Microsoft does not support manually changing Defender service and driver start types in Windows images, and a stopped Defender service can be expected where a non-Microsoft antivirus product is active.
A failed scan is serious, not a complete protection verdict
A failed scan is a visibility problem. If an on-demand or scheduled scan cannot complete during an investigation, the endpoint team has lost a useful detection and assurance mechanism at precisely the wrong moment. If the Defender service is genuinely stopped and real-time protection is disabled, the situation is more serious.
Still, a scan crash alone doesn’t prove the machine was wholly unprotected throughout the event. Real-time protection may have been active until the failure, the service may have restarted, or another approved endpoint product may be the active antivirus. The reverse also applies: an installed Defender icon means little if RealTimeProtectionEnabled is false, signatures are stale or the service fails whenever a scan begins.
Where the update is current and scanning still fails, treat it as a local fault until evidence says otherwise. Check for competing security products, review recent endpoint-agent changes and inspect the Defender Operational log. If there is a credible reason to suspect compromise, use an approved second-opinion scanner or follow the organisation’s incident-response process rather than assuming this incident explains every symptom.
The operational lesson: signatures are production changes
This isn’t an argument for holding threat intelligence updates back for days. That simply trades a short-lived reliability risk for longer exposure to current malware. The useful lesson is that rapid security content still needs observability and control.
Microsoft recommends a gradual, ring-based approach for Defender deployments, explicitly describing staged rollout as a way to identify problems in an organisation’s own environment before wider release. For large estates, the first ring should cover representative hardware, Windows versions, network paths and security-tool combinations — not just a few IT laptops.
Monitor the outcome, not just the installation event: service state, signature freshness, real-time-protection status and a lightweight scan-health signal. Teams also need a pre-agreed response when protection content misbehaves: pause broad approval where their tooling permits it, obtain the corrected intelligence package from a trusted Microsoft source, use compensating controls where required, and record the event as a security-control outage.
The Microsoft Defender crash fix is welcome, but it shouldn’t be waved away as a trivial definitions glitch. Antivirus content is part of the production security stack. It deserves the staged deployment, telemetry, rollback thinking and change discipline applied to every other component that can affect a business — or a home user trying to establish whether their PC is safe.
Sources and further reading
- BleepingComputer: report on the Microsoft Defender Antivirus crash issue and reported fix
- Microsoft Learn: Microsoft Defender Antivirus security intelligence, engine and platform updates
- Microsoft Learn: managing Defender protection update sources and frequency
- Microsoft Support: checking Defender protection updates in Windows Security
- Microsoft Learn: Get-MpComputerStatus PowerShell reference
- Microsoft Learn: deploying Microsoft Defender Antivirus in rings


