HardBreacher: Nightmare Eclipse Drops Kaspersky Endpoint Security Exploit
The independent researcher known as Nightmare Eclipse (also called Chaotic Eclipse) has publicly released a proof-of-concept exploit dubbed HardBreacher targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. The researcher, who has built a reputation over recent months for publishing zero-day exploits primarily affecting Windows and Microsoft Defender, began disclosing flaws after growing frustrated with Microsoft's handling of vulnerability reports. While many of the dropped exploits remained at the PoC stage, several were picked up by malicious actors and exploited in the wild.
According to Nightmare Eclipse, HardBreacher gives an attacker control over the Kaspersky UI process, with severe downstream effects. "The Kaspersky completely loses it when you take control over the UI process — you can cause it to stop functioning, grant or block access to files it's not supposed to," the researcher said, adding that a successful run leaves the operating system in an unstable state. The PoC code, the researcher noted, is rough around the edges but functional. The disclosure follows other recent Nightmare Eclipse drops including ShieldBreak, which spawns a shell with System privileges, and LegacyHive, another privilege escalation exploit.
Kaspersky confirmed to SecurityWeek that the underlying issue has been resolved and is being delivered automatically to customers. "The corresponding fix is delivered via an automatic update, or users can trigger a database update manually," the company stated. Endpoint users should verify their Kaspersky signature databases are current to ensure protection. Administrators responsible for managed fleets can validate their network exposure using a port scanner to confirm endpoint agents are reporting and communicating with management consoles as expected.
The HardBreacher disclosure underscores a recurring concern: when defenders drop working exploit code publicly, it lowers the barrier for opportunistic attackers who can weaponize it within hours. Security teams should patch immediately, audit endpoint telemetry for signs of UI process tampering, and review user privilege assignments. Practitioners auditing their broader security posture — from exposed services to certificate hygiene — can run an SSL/TLS checker against management infrastructure and check administrator credentials with a password checker to reduce the attack surface beyond the patched vulnerability.