Kaspersky zero-day exploit drops rogue DLL on patched Windows

Researcher Chaotic Eclipse published HardBreacher, a working exploit for a Kaspersky Endpoint Security privilege escalation zero-day.

CSBadmin
2 Min Read

Kaspersky Endpoint Security now has a public, working exploit for a privilege escalation zero-day. The proof of concept, called HardBreacher, comes from researcher Chaotic Eclipse, who also operates under the name Nightmare Eclipse.

The PoC targets fully patched Windows 11 25H2 systems running Kaspersky Endpoint v14.0.0.504. The researcher warns it is unstable and may require repeated attempts. When it succeeds, it plants MY_SNAKE_IS_SOLID.dll in System32 with full permissions for the current user. Taking control of Kaspersky’s UI process can stop the antivirus from functioning and let an attacker grant or block file access, leaving the entire operating system in an unstable state. Chaotic Eclipse described the release as “duct taped” and said rerunning it is expected behavior.

Kaspersky said it has already addressed the vulnerability. Chaotic Eclipse is known for publishing working exploits after criticizing how vendors handle vulnerability reports, with past releases targeting Windows and Microsoft Defender, including the Undefend and RedSun zero-days. Some of those exploits were later used in the wild, fueling debate over responsible disclosure versus public PoC releases.

Enterprises running Kaspersky Endpoint Security should confirm the latest updates are installed and watch for unexpected DLLs appearing in System32. A public, working exploit makes even an unstable bug easy to weaponize, so patch verification matters more than usual.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.