Zero Day Room
Live
Vulnerabilities

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day

Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, has released three new zero-day exploits

Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, has released...

Nightmare Eclipse, a security researcher known for targeting Microsoft products, has recently shifted focus to other vendors, releasing three new zero-day exploits last week.

The exploits, dubbed PrettyPrague, FalconFlank, and GreenSection, target Avast's sandbox, CrowdStrike Falcon Sensor's Office macros remediation feature, and Nvidia's shared global memory section, respectively.

GenDigital, the parent company of Avast, has confirmed awareness of the vulnerability affecting Avast Antivirus and other Gen products, stating they have initiated security response procedures and fixed the issue.

CrowdStrike is actively investigating the FalconFlank exploit and advises customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting.

Nvidia is reviewing the GreenSection exploit, which targets an out-of-bounds memory write in its GPU display driver components, noting it can be used to cross user boundaries or compromise the dwm.exe process.

Kevin Beaumont, a security researcher, has confirmed that the Avast, CrowdStrike, and Kaspersky exploits are valid.

Nightmare Eclipse initially gained notoriety for zero-day exploits targeting Microsoft products but has since expanded to other vendors.

Kaspersky patched a privilege escalation zero-day in its endpoint security product, HardBreacher, in late August.

Nightmare Eclipse's latest exploits highlight the ongoing threat of zero-day vulnerabilities and the importance of timely patching and security updates.

Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, has released three new zero-day exploits targeting Avast, CrowdStrike, and Nvidia products.

The PrettyPrague exploit targets the Avast sandbox to spawn a shell with full system privileges, potentially affecting other GenDigital products like AVG and Norton.

GenDigital has confirmed the vulnerability and stated they have fixed the issue, urging users to keep their products up to date.

FalconFlank exploits a bug in CrowdStrike Falcon Sensor's Office malicious macros remediation feature for privilege escalation.

CrowdStrike is investigating the claims and advises customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting.

Nvidia is reviewing the GreenSection exploit, which targets an out-of-bounds memory write in its GPU display driver components.

Kevin Beaumont has confirmed the validity of the Avast, CrowdStrike, and Kaspersky exploits.

Nightmare Eclipse's latest exploits show the need for vigilance and prompt security updates in the face of emerging threats.

Related coverage

More from Vulnerabilities