< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Chaotic Eclipse releases zero-day exploits for Kaspersky and Avast

Security researcher Chaotic Eclipse, also known as Nightmare Eclipse, has released two new zero-day proof-of-concept (PoC) exploits targeting major antivirus software.

The first exploit, named ‘HardBreacher’, targets Kaspersky Endpoint Security. It allows for privilege escalation on fully patched Windows 11 25H2 systems running Kaspersky Endpoint v14.0.0.504. The researcher noted that successful exploitation can create a DLL in System32 with full user permissions and potentially disrupt the antivirus UI process, interfering with file-access controls. Kaspersky has stated it has already addressed this vulnerability.

The second exploit, named ‘PrettyPrague’, targets Gen Digital’s Avast Antivirus. This flaw exploits the Avast Sandbox to dump the Windows SAM database and gain a SYSTEM-level shell. The researcher claims the PoC works on fully patched versions of Avast Antivirus and Windows 11 25H2, and suggests the vulnerability may also affect other Gen Digital products such as AVG and Norton.

Entities

Avast · Gen Digital · Kaspersky