The researcher often called Nightmare Eclipse has dropped one other zero-day — this time a privilege escalation exploit focusing on a Kaspersky endpoint safety product.
Nightmare Eclipse, also called Chaotic Eclipse, has launched PoC exploits for a lot of vulnerabilities in latest months, primarily Home windows and Microsoft Defender flaws.
The researcher began dropping zero-days after rising annoyed with Microsoft’s dealing with of vulnerability stories. Whereas most of the exploits remained on the PoC stage, a couple of ended up being exploited within the wild by malicious actors.
Over the weekend, Nightmare Eclipse launched an exploit focusing on a privilege escalation vulnerability in Kaspersky Endpoint Safety. The exploit has been dubbed HardBreacher.
“The PoC is just not in the most effective form in any respect, it’s mainly duct tapped, I simply managed to make it work and that’s all,” the researcher famous.
“The fascinating half about that is the Kaspersky utterly loses it if you take management over the UI course of, you may trigger it to cease functioning, grant/block entry to recordsdata its not speculated to, if the PoC succeeds, the whole working system turns into a scorching mess,” the researcher added.
Contacted by SecurityWeek, Kaspersky stated the underlying concern has been resolved.
“The corresponding repair is delivered through an computerized replace, or customers can set off a database replace manually,” Kaspersky acknowledged.
Different exploits made public not too long ago by Nightmare Eclipse embrace ShieldBreak, which permits an attacker to spawn a shell with System privileges, and LegacyHive, which allows privilege escalation.
Associated: Log4j Distant Code Execution Scare
Associated: Essential Ruby on Rails Vulnerability in Attackers’ Crosshairs
Associated: Extra Particulars Emerge on Exploited PaperCut Vulnerabilities







