Zero Day Room
Live
Defence

Kaspersky Endpoint Exploit Released by Researcher

A researcher has published a proof-of-concept exploit for a privilege escalation flaw in Kaspersky Endpoint Security.

Defence: A researcher has published a proof-of-concept exploit for a privilege escalation flaw in Kaspersky Endpoint Security

The researcher known as Nightmare Eclipse has released a proof-of-concept exploit for a privilege escalation vulnerability in Kaspersky Endpoint Security. The exploit, called HardBreacher, was made public over the weekend.

Nightmare Eclipse also uses the alias Chaotic Eclipse. This researcher has a recent history of publishing zero-day exploits. The activity reportedly began after frustration with Microsoft's vulnerability reporting process.

In a statement, the researcher described the HardBreacher proof-of-concept as rudimentary. "The PoC is not in the best shape at all, it is basically duct taped, I just managed to make it work and that’s all," Nightmare Eclipse noted.

The researcher claimed the exploit's impact is severe. Taking control of the user interface process can cause the security software to malfunction. This could allow an attacker to improperly grant or block file access. The entire operating system becomes a hot mess if the PoC succeeds.

Kaspersky Issues Fix

Kaspersky told SecurityWeek that the underlying security issue has been resolved. The company stated the fix is being delivered through its standard update channels. A Kaspersky spokesperson said the corresponding fix is delivered via an automatic update, or users can trigger a database update manually.

This indicates the vulnerability is patched for users with updated security databases. The company's response suggests the flaw was addressed before the public exploit release.

Researcher's Exploit History

Nightmare Eclipse has released several other proof-of-concept exploits recently. Many have targeted Windows and Microsoft Defender components. Most remained as proofs-of-concept. A few were later exploited by malicious actors in real-world attacks.

Two other notable exploits from the researcher are ShieldBreak and LegacyHive. ShieldBreak allows an attacker to spawn a shell with System privileges. LegacyHive is another tool that enables privilege escalation. The pattern of proof-of-concept releases turning into active threats is a key security metric.

Vulnerability Management Context

The release highlights an ongoing challenge. Unpatched vulnerabilities exist even in security products. Endpoint protection platforms can contain flaws. If exploited, they compromise the very systems they are meant to defend. It shows the critical importance of maintaining automatic updates for all security software. This principle applies to managing scheduled patches across an enterprise.

Kaspersky's deployment of a fix via automatic update is a standard response. It places the onus on users to ensure their software is current. Protection depends on it.

The researcher's actions continue a pattern. Zero-day exploits are being publicly disclosed outside of coordinated vendor disclosure programs.

Related coverage

More from Defence