Researcher Nightmare Eclipse, also known as Chaotic Eclipse/MSNightmare, publicly released HardBreacher, a proof of concept for a claimed local privilege-escalation flaw in Kaspersky Endpoint Security. The unstable PoC was reportedly tested against version 14.0.0.504 on fully patched Windows 11 25H2 and can intermittently create C:\Windows\System32\MY_SNAKE_IS_SOLID.dll with permissions granted to the invoking user. The researcher says control of a Kaspersky UI process can also destabilize the security product and affect its file-access decisions.
Kaspersky told SecurityWeek that it fixed the underlying issue and delivered the remediation through its automatic update mechanism, with a manual database update also available. No CVE, affected-version range, technical root cause, or confirmed in-the-wild exploitation has been published; other reporting had not yet identified a public vendor advisory. Organizations using Kaspersky Endpoint Security should ensure updates are applied, investigate unexpected DLL creation under System32, anomalous Kaspersky UI-process activity, and security-service failures, and avoid executing the public PoC on production endpoints.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Kaspersky told SecurityWeek that it resolved the underlying Kaspersky Endpoint Security issue and distributed the fix through its automatic update mechanism. Users can also manually trigger a database update to obtain the fix.
Nightmare Eclipse (MSNightmare/Chaotic Eclipse) publicly released HardBreacher, an unstable proof of concept alleging a local privilege-escalation zero-day in Kaspersky Endpoint Security. The PoC was reportedly tested against version 14.0.0.504 on fully patched Windows 11 25H2 and claims it can create a user-controllable DLL in System32.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
meetcyber.net
Open sourcexakep.ru
Open sourcesecurityaffairs.com
Open sourcecyberveille.ch
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.