Zero-Day Exploit Targets Kaspersky Endpoint Security in Privilege Escalation Attack
Researcher Nightmare Eclipse (also known as Chaotic Eclipse) has released a new zero-day exploit, HardBreacher, targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. The exploit, disclosed over the weekend, allows attackers to compromise the security product’s UI process, potentially causing system instability, unauthorized file access, or complete operational failure.
Nightmare Eclipse, known for publicly disclosing unpatched flaws primarily in Windows and Microsoft Defender began releasing zero-days after criticizing Microsoft’s vulnerability handling. While most exploits remain proof-of-concept (PoC), some have been weaponized by threat actors in real-world attacks.
The HardBreacher PoC, described by the researcher as hastily assembled, demonstrates how exploiting the flaw can disrupt Kaspersky’s functionality, leading to system-wide instability. Kaspersky confirmed the issue has been patched via automatic updates, though users can manually trigger a database update for immediate protection.
This disclosure follows other recent exploits from Nightmare Eclipse, including ShieldBreak (enabling SYSTEM-level shell access) and LegacyHive (another privilege escalation tool). The trend underscores ongoing risks from unpatched vulnerabilities in widely used security software.
Source: https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/
Kaspersky cybersecurity rating report: https://www.rankiteo.com/company/kaspersky
"id": "KAS1788193712",
"linkid": "kaspersky",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'Kaspersky',
'type': 'Cybersecurity Company'}],
'attack_vector': 'Zero-Day Exploit',
'description': 'Researcher Nightmare Eclipse (also known as Chaotic Eclipse) '
'has released a new zero-day exploit, HardBreacher, targeting '
'a privilege escalation vulnerability in Kaspersky Endpoint '
'Security. The exploit allows attackers to compromise the '
'security product’s UI process, potentially causing system '
'instability, unauthorized file access, or complete '
'operational failure.',
'impact': {'operational_impact': 'System instability, unauthorized file '
'access, complete operational failure',
'systems_affected': 'Kaspersky Endpoint Security'},
'motivation': 'Public disclosure of unpatched flaws, criticism of '
'vulnerability handling',
'post_incident_analysis': {'corrective_actions': 'Patch released via '
'automatic updates',
'root_causes': 'Unpatched vulnerability in '
'Kaspersky Endpoint Security UI '
'process'},
'references': [{'source': 'Researcher Nightmare Eclipse'}],
'response': {'containment_measures': 'Automatic updates for patching, manual '
'database update option',
'remediation_measures': 'Patch released via automatic updates'},
'threat_actor': 'Nightmare Eclipse (Chaotic Eclipse)',
'title': 'Zero-Day Exploit Targets Kaspersky Endpoint Security in Privilege '
'Escalation Attack',
'type': 'Privilege Escalation',
'vulnerability_exploited': 'Privilege escalation vulnerability in Kaspersky '
'Endpoint Security UI process'}