Researcher Publishes HardBreacher Exploit Targeting Kaspersky Endpoint
The public release raises immediate operational risk for administrators while Kaspersky says a database update has fixed the flaw.
Overview
- The researcher known as Chaotic or Nightmare Eclipse released a proof-of-concept called HardBreacher over the weekend that targets Kaspersky Endpoint Security.
- The exploit is a local privilege escalation that the researcher says can write a DLL into C:\Windows\System32 and take control of Kaspersky’s UI process, which can disrupt the antivirus and file-access controls when it succeeds.
- The PoC is described by the author as unstable and often fails, but similar public releases from the same researcher have later been turned into real-world attacks, so even unreliable code can raise real risk.
- Kaspersky told reporters it has addressed the underlying issue and delivered a fix via automatic updates or a manual database update for affected Endpoint builds.
- System administrators should apply Kaspersky updates, monitor for signs of the exploit, and consider temporary hardening steps for endpoints while the debate over public PoC disclosure and vendor response continues.