<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

PoC Claims Zero-Day Privilege Escalation in Kaspersky Endpoint Security

Researcher MSNightmare claims a zero-day in Kaspersky Endpoint Security on Windows 11; Kaspersky says a fix is already shipping.
Content Team

A researcher known as MSNightmare — also tracked as Nightmare Eclipse and Chaotic Eclipse — has published a proof-of-concept called HardBreacher, claiming a local privilege-escalation zero-day in Kaspersky Endpoint Security on fully patched Windows 11 (version 25H2), running product version 14.0.0.504.

If real, a low-privileged user could write a DLL to System32 — normally off-limits — and seize a Kaspersky UI process, letting them stop the product, override its allow-or-block decisions, and destabilize the operating system. The researcher's previous drops have a mixed record: some stayed proof-of-concept, others ended up in active attacks.

Kaspersky says it has already addressed the issue, with the fix delivered through an automatic update — users can also trigger a database update manually. No CVE has been assigned. The PoC is unstable, error-prone, and requires multiple attempts.

Organizations should confirm their Kaspersky databases are current, review process telemetry, and avoid running the public code on production systems.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo