HardBreacher PoC exploits Kaspersky Endpoint Security
Researcher Nightmare Eclipse published HardBreacher, a proof-of-concept privilege escalation exploit for Kaspersky Endpoint Security; Kaspersky deployed an automatic update to address it.
Over the weekend, security researcher Nightmare Eclipse released HardBreacher, a proof-of-concept privilege escalation exploit that targets Kaspersky Endpoint Security. The exploit focuses on the product’s user interface process and can cause the security software and the host operating system to behave unpredictably if it succeeds.
Nightmare Eclipse described the PoC as rough and intended only to demonstrate the flaw. “The PoC is not in the best shape at all, it is basically duct taped, I just managed to make it work and that’s all,” the researcher wrote. The post added that taking control of the UI process can make Kaspersky “stop functioning, grant/block access to files its not supposed to,” and that when the PoC succeeds “the entire operating system becomes a hot mess.”
Kaspersky confirmed the underlying vulnerability has been fixed and that the correction was distributed through its update systems. “The corresponding fix is delivered via an automatic update, or users can trigger a database update manually,” the company stated, and urged customers to ensure installations are up to date so they receive the corrective update.
Privilege escalation vulnerabilities allow an attacker with some level of access to increase their rights on a device. Exploits of this type can let an attacker run code with higher system privileges or interfere with endpoint protection behavior, which can raise the impact of other malware or intrusion techniques.
Nightmare Eclipse has published several other proof-of-concept exploits in recent months, including ShieldBreak, which spawns a shell with System privileges, and LegacyHive, another privilege escalation method. The researcher increased public releases after expressing frustration with how some vulnerability reports were handled. A subset of the publicly released PoCs has later been observed being used by malicious actors.
Administrators running Kaspersky Endpoint Security should verify that automatic updates are active or perform a manual database update to ensure the fix is applied.








