Researcher Nightmare Eclipse releases three zero-day exploits
Nightmare Eclipse published proof-of-concept code for three zero-day exploits-PrettyPrague, FalconFlank and GreenSection-affecting Avast, CrowdStrike and Nvidia products.
Security researcher Nightmare Eclipse, who also uses the aliases Chaotic Eclipse, Infinite Nightmare and MSNightmare, published proof-of-concept code last week for three zero-day exploits: PrettyPrague, FalconFlank and GreenSection. The exploits target Avast products, CrowdStrike Falcon Sensor and multiple Nvidia user-mode components.
PrettyPrague targets the Avast sandbox and can spawn a shell with full system privileges when code runs inside the sandbox, the researcher wrote. The researcher added the bug may affect other GenDigital products, including AVG and Norton. GenDigital acknowledged a vulnerability affecting a subset of its products and provided a statement: “We immediately initiated our security response procedures and have fixed the issue. We take all security matters seriously and encourage users to keep their products up to date to ensure they are protected.” GenDigital confirmed updates have been pushed to affected products.
FalconFlank exploits a flaw in the Microsoft Office malicious macros remediation feature of the CrowdStrike Falcon Sensor to escalate privileges, the researcher wrote. CrowdStrike is investigating and issued guidance advising customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while relying on Cloud Anti-malware for Microsoft Office Files protections. CrowdStrike also directed customers to a FalconFlank technical alert in its support portal.
GreenSection targets an out-of-bounds memory write in a global memory section shared by several Nvidia user-mode components. The researcher wrote the bug does not grant SYSTEM privileges immediately but can be used to cross user boundaries or to affect the dwm.exe process. Nvidia had not provided a statement at the time of reporting.
In late August the same researcher disclosed a privilege-escalation zero-day against a Kaspersky endpoint product, dubbed HardBreacher, which Kaspersky patched on August 31. Independent security researcher Kevin Beaumont reported that the Avast, CrowdStrike and Kaspersky exploits were functional when he examined them late last week.
The proof-of-concept releases occurred within a short window last week. GenDigital’s fix is available through product updates and customers are urged to apply them. CrowdStrike’s guidance is offered as a temporary mitigation while it continues its investigation. No public mitigation guidance from Nvidia was available at the time of reporting.








