Nightmare Eclipse drops Kaspersky product exploit “HardBreacher”.

Nightmare Eclipse drops Kaspersky product exploit “HardBreacher”.

The researcher known as Nightmare Eclipse has released another zero-day attack – this time a privilege escalation exploit targeting a Kaspersky Endpoint security product.

Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws.

The researcher began dropping zero-day approaches after becoming frustrated with Microsoft’s handling of vulnerability reports. While many of the exploits were still in the PoC stage, some were eventually exploited by malicious actors.

Over the weekend, Nightmare Eclipse released an exploit that targets a privilege escalation vulnerability in Kaspersky Endpoint Security. The exploit has been synchronized HardBreacher.

“The PoC is not in the best shape at all, it’s basically plumbed, I just managed to get it to work and that’s all,” the researcher noted.

“The interesting thing is that Kaspersky completely loses control over the UI process. They can cause it to stop working, grant/block access to files, which is actually not the case, and if the PoC is successful, the entire operating system becomes a mess,” the researcher added.

Advertising. Scroll to continue reading.

Contacted by Safety WeekKaspersky said the underlying problem was resolved.

“The appropriate fix will be delivered via an automatic update, or users can manually trigger a database update,” Kaspersky explained.

Other exploits recently released by Nightmare Eclipse include ShieldBreak, which allows an attacker to spawn a shell with system privileges, and LegacyHive, which enables privilege escalation.

Related: Fear of Log4j remote code execution

Related: Critical Ruby on Rails vulnerability in attackers’ crosshairs

Related: More details about exploited PaperCut vulnerabilities known

Leave a Reply

Your email address will not be published. Required fields are marked *