Kaspersky Endpoint Security HardBreacher Exploit Patched

Kaspersky has quietly fixed a flaw in its Endpoint Security product after independent researcher Nightmare Eclipse published a proof-of-concept exploit dubbed HardBreacher, which claims to abuse a zero-day privilege escalation issue in the Windows client.[1][2][6]

The HardBreacher code, released publicly by Nightmare Eclipse, targets Kaspersky Endpoint Security running on Windows and attempts to let an unprivileged user write a DLL file named MY_SNAKE_IS_SOLID.dll into the C:WindowsSystem32 directory while granting full permissions to that object, behavior that would indicate a breakdown in Windows privilege boundaries if reliably reproduced.[1][2][6] The researcher’s GitHub description frames the bug as a “Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability” and lists Kaspersky Endpoint Security 14.0.0.504 on Windows 11 25H2 as the tested configuration.[2]

In comments shared with industry publication SecurityWeek, Kaspersky said the underlying issue has been resolved and that the corresponding fix is being delivered automatically via its database update mechanism, with users also able to trigger a manual update of the antivirus databases.[1][6] Russian outlet SecurityLab reported that Kaspersky’s remediation is bundled into antivirus database releases dated August 30, 2026 and later, effectively turning the fix into a silent patch rather than a traditional product hotfix.[1] As of August 31, no CVE identifier has been assigned and Kaspersky has not published a standalone advisory detailing the vulnerability or listing affected versions.[1][2]

Despite the “zero-day” branding, HardBreacher currently remains an experimental proof-of-concept rather than a fully validated exploit, and independent researchers have yet to confirm the behavior described by Nightmare Eclipse on other systems or configurations.[1][2] SecurityLab notes that HardBreacher is unstable and that there is no independent reproduction of the claimed privilege escalation, which leaves open questions about how broadly the flaw could be abused in real-world environments.[1] There have been no public reports of in-the-wild exploitation tied to HardBreacher, and SecurityWeek’s coverage describes the researcher as a prolific finder of endpoint flaws rather than attributing the activity to a criminal or state-backed threat group.[2][6]

In its statement, Kaspersky emphasized that the product “loses it” when the UI process is taken over, allowing an attacker to disrupt protection and manipulate file access rules if the proof-of-concept executes successfully, turning the operating system into what the researcher called “a hot mess.”[6] That description underscores that even a local-only elevation-of-privilege issue can have outsized impact in endpoint security tooling, enabling attackers who already have a foothold on a machine to disable defenses or create persistence in protected directories.[2][6] For enterprises that rely on Kaspersky Endpoint Security to enforce policy and block malware, that scenario raises the stakes for ensuring all endpoints receive the updated databases that include the HardBreacher fix.[1][6]

Organizations running Kaspersky Endpoint Security should verify that database updates from August 30, 2026 or later have been deployed across their fleets and confirm that endpoints are configured to receive automatic updates from Kaspersky’s cloud or on-premises servers.[1][6] Admins using Kaspersky Endpoint Security Cloud or related management consoles can also review the patch and update lists in their vulnerability and patch management sections to ensure that all relevant fixes for detected software vulnerabilities have been applied, and that older database snapshots are not lingering on critical systems.[13][15] Until Kaspersky publishes a formal advisory with technical details, defenders may want to treat HardBreacher as a high-impact but locally exploitable risk and continue to monitor for any new reproduction reports or indicators of real-world abuse.[1][2][6]

References

  1. Nightmare Eclipse теперь против Касперского. На GitHub …
  2. Kaspersky Zero-Day Exploit Writes DLL Into Windows System32
  3. Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
  4. Viewing the list of updates – Kaspersky Support
  5. Patch Management

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply