Live Cybersecurity News Ticker | Codekeeper

PoC Claims Zero-Day Privilege Escalation in Kaspersky Endpoint Security

Written by Content Team | Sep 1, 2026, 12:47:11 PM

A researcher known as MSNightmare — also tracked as Nightmare Eclipse and Chaotic Eclipse — has published a proof-of-concept called HardBreacher, claiming a local privilege-escalation zero-day in Kaspersky Endpoint Security on fully patched Windows 11 (version 25H2), running product version 14.0.0.504.

If real, a low-privileged user could write a DLL to System32 — normally off-limits — and seize a Kaspersky UI process, letting them stop the product, override its allow-or-block decisions, and destabilize the operating system. The researcher's previous drops have a mixed record: some stayed proof-of-concept, others ended up in active attacks.

Kaspersky says it has already addressed the issue, with the fix delivered through an automatic update — users can also trigger a database update manually. No CVE has been assigned. The PoC is unstable, error-prone, and requires multiple attempts.

Organizations should confirm their Kaspersky databases are current, review process telemetry, and avoid running the public code on production systems.

Source: Cybersecurity News