HardBreacher PoC Puts Kaspersky Endpoint Security on Edge
SecurityWeek says Nightmare Eclipse, also known as Chaotic Eclipse, has released HardBreacher, a public proof of concept for a privilege-escalation flaw in Kaspersky Endpoint Security. Kaspersky told SecurityWeek the issue is fixed and the update is available through its automatic database channel or a manual database update.
The exploit works by taking control of the product’s UI process rather than stealing credentials. In Nightmare Eclipse’s description, that makes the agent misbehave: it can stop functioning and make the wrong allow-or-block decisions about files, and a successful run can leave the operating system unstable.
The immediate risk is for endpoints that have not yet picked up Kaspersky’s fix. If Kaspersky Endpoint Security sits as the decision point between users and files, a local foothold can turn into control over the protector itself, and public exploit code raises the odds of copycat use before the patch lands.