The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike and Nvidia.
Also known as Chaotic Eclipse, Infinite Nightmare and MSNightmare, the security researcher became famous for a series of zero-day exploits targeting Microsoft products, but has recently moved on to other vendors as well.
In late August, Nightmare Eclipse released a zero-day for privilege escalation in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit was patched by Kaspersky on August 31.
In a short window last week, Nightmare Eclipse released three new zero-day exploits called PrettyPrague, FalconFlank, and GreenSection.
The Beautiful Prague The proof-of-concept (PoC) code, according to the researcher, targets Avast’s sandbox to create a shell with full system privileges and may also affect other GenDigital products, including AVG and Norton.
“Gen was recently notified of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate system privileges. We immediately initiated our security response procedures and fixed the issue. We take all security issues seriously and encourage users to keep their products up-to-date to ensure they are protected,” a GenDigital spokesperson said in response to Security Week query.
Falcon flank used a bug in CrowdStrike Falcon Sensor’s Office malicious macro remediation feature for privilege escalation, researcher says.
“We are actively investigating these allegations and are advising customers to disable the Windows policy setting to remove suspicious Microsoft Office File macros. Customers remain protected through the Cloud Anti-malware settings for Microsoft Office Files. We are directing customers to the FalconFlank Tech Alert on the CrowdStrike Support Portal,” CrowdStrike said Security Week.
The GreenSection the exploit, Nightmare Eclipse says, targets an out-of-memory write affecting a shared global section of memory used by multiple Nvidia user-mode components.
“While this bug doesn’t immediately gain SYSTEM privileges, it can easily be exploited between users or even compromise the dwm.exe process. I haven’t looked into it in depth, but I’d love to see someone make a full exploit of it,” notes Nightmare Eclipse.
Security researcher Kevin Beaumont said late last week that Avast, CrowdStrike and Kaspersky were working.
Security Week emailed Nvidia for a statement on the exploit and will update this article if the company responds.
Related: VMware Workstation and Fusion updates fix critical vulnerability
Related: Google Patches 6th Chrome Zero-Day of 2026
Related: Over 3 million WordPress sites affected by migration plugin vulnerability
Related: Cisco warns of unpatched flaws in secure email, fixes critical switch vulnerabilities