Home About Services Support Contact Projects Blog
216.785.2700 support@microadv.com Login

Microsoft Fixes Defender Scan Crashes After Recent Update

Microsoft has released a fix for a Microsoft Defender issue that caused some Windows users to experience Quick Scan and Full Scan crashes after recent security intelligence updates.

The problem started appearing around August 18, 2026, when users and IT administrators noticed that Defender scans would begin normally but fail before completion. In some cases, Windows Security reported that the threat protection service had stopped.

Microsoft has since addressed the issue with a newer Defender Security Intelligence update.

What Was Happening?

Affected systems could launch a malware scan, but Defender would sometimes stop unexpectedly before finishing.

Reports included problems with:

  • Quick Scan

  • Full Scan

  • Scheduled scans

  • Microsoft Defender Offline Scan

Some users checking Windows Event Viewer also found crashes involving:

MsMpEng.exe

and

mpengine.dll

The error code commonly reported was 0xC0000005, which generally points to an application memory access violation.

Because the same issue appeared on multiple unrelated systems, it became clear that this was not simply an isolated Windows problem or a sign that every affected machine was infected with malware.

Microsoft Released a Fix

Microsoft confirmed the Defender scan problem and released an updated security intelligence package to correct it.

The corrected version is:

Microsoft Defender Security Intelligence 1.457.236.0 or later

Since Defender updates frequently, many Windows systems may already be running a newer version automatically.

Users who experienced scan failures should still check their Defender update status and run another scan afterward.

How to Check Your Defender Updates

Open:

Windows Security → Virus & threat protection → Protection updates

Then select:

Check for updates

Once the update completes, verify that the Security Intelligence version is 1.457.236.0 or newer.

After that, run another Quick Scan to confirm Defender is working normally again.

Does a Defender Crash Mean You Have Malware?

Not necessarily.

A scan crashing does not automatically mean the computer is infected.

The issue was tied to Microsoft Defender itself, and similar failures were reported across otherwise healthy systems.

However, if you were already investigating suspicious activity when the problem occurred, don't assume everything was caused by the Defender bug.

Update Defender first, verify that scans complete normally, and then continue the original security investigation.

What IT Administrators Should Check

Businesses using Microsoft Defender or Microsoft Defender for Endpoint should take a few additional steps.

Administrators should verify that:

  • Defender Security Intelligence is current across managed devices.

  • Quick and scheduled scans complete successfully.

  • Defender services are not unexpectedly crashing.

  • Endpoints are successfully receiving security intelligence updates.

  • Any devices that were already under investigation are rescanned after updating.

This is especially important in larger environments where laptops or remote devices may not receive updates at the same time.

A Useful Reminder for IT Teams

This incident highlights an important point about endpoint security.

Seeing Microsoft Defender enabled does not necessarily mean every Defender function is operating correctly.

Organizations should monitor more than just whether antivirus protection is turned on. Scan completion, definition updates, service health, patching, endpoint visibility, and security telemetry are all important parts of a healthy IT environment.

If multiple computers suddenly start showing the same antivirus behavior at roughly the same time, administrators should also consider the possibility of a bad software or definition update before spending hours rebuilding systems.

Need Help Reviewing Your Business IT Environment?

For businesses, issues like this are also a good reason to periodically review the broader technology environment—not just a single antivirus application.

MicroAdvantage can help businesses evaluate their IT infrastructure, security posture, endpoint protection, patching, network configuration, backups, and other technology risks.

A professional infrastructure review can help identify outdated systems, security gaps, configuration issues, and other weaknesses before they turn into larger problems.

Whether your organization is dealing with Microsoft Defender issues or simply wants a better understanding of its current technology environment, MicroAdvantage can help review the existing setup and identify practical areas for improvement.

Bottom Line

Microsoft Defender's recent scan crashes were caused by a software issue rather than evidence that every affected computer had been compromised.

Microsoft has now released a fix through Security Intelligence version 1.457.236.0 or later.

For most Windows users, the recommended action is simple: update Microsoft Defender, run another Quick Scan, and confirm that scanning completes normally.

For businesses, this is also a good opportunity to review endpoint security and overall infrastructure health to make sure systems are properly updated, monitored, and protected.

« Back to the blog