Particle.news

Nightmare Eclipse Publishes Zero-Day Exploits Targeting CrowdStrike, Avast and Nvidia

Public proof-of-concept code prompting vendor fixes or workarounds increases immediate risk for Windows administrators.

Overview

  • A prolific researcher using the name Nightmare Eclipse has posted working proof-of-concept exploits for CrowdStrike Falcon Sensor, GenDigital’s Avast products, and multiple NVIDIA user-mode components.
  • The CrowdStrike PoC called FalconFlank abuses the Falcon Sensor’s Microsoft Office file malicious macro removal remediation to escalate local privileges and has no public CVE or full public advisory at this time.
  • GenDigital confirmed it fixed the vulnerability exploited by the PrettyPrague PoC against Avast and advised customers to keep products up to date, while Kaspersky had already issued a patch for an earlier exploit from the same researcher.
  • The NVIDIA PoC called GreenSection exploits a shared global memory section at \BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba} to trigger an out-of-bounds write that can cross user boundaries or impact dwm.exe but does not immediately yield SYSTEM privileges.
  • System administrators should apply available vendor updates, follow vendor mitigation guidance such as CrowdStrike’s recommendation to disable the Microsoft Office File Suspicious Macro Removal policy, and monitor endpoints for signs of local privilege escalation as the disclosure-versus-coordination debate continues.