Zero-day hunter adds Avast and Nvidia bugs to a CrowdStrike streak

Nightmare Eclipse adds Avast and Nvidia zero-day exploits to its CrowdStrike drop, and Gen says the Avast bug is fixed.

CSBadmin
2 Min Read

The researcher known as Nightmare Eclipse has added two more vendor zero-days to an already busy month, releasing proof-of-concept exploits for an Avast sandbox escape and an Nvidia memory corruption bug days after a CrowdStrike privilege escalation drop.

The Avast exploit, dubbed PrettyPrague, targets the vendor’s sandbox to spawn a shell with full system privileges. Its author notes the bug may also affect other Gen Digital products, including AVG and Norton. Gen responded that it was recently made aware of the issue, has fixed it, and encourages users to keep products updated.

The Nvidia finding, named GreenSection, corrupts memory past the bounds of a shared global section used by multiple user-mode components. According to the researcher, the flaw does not hand over SYSTEM right away but slips across user boundaries with ease and could take down the dwm.exe process. Nvidia had not commented on the finding as of publication.

Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, built a reputation on Microsoft zero-day exploits before branching to endpoint vendors. Late August brought a Kaspersky product exploit that the vendor patched on August 31, and the CrowdStrike FalconFlank PoC released days ago abuses the Office malicious macro remediation feature, with CrowdStrike advising customers to disable that policy setting while it investigates. Independently, researcher Kevin Beaumont weighed in, saying he had tested and validated the Avast, CrowdStrike and Kaspersky proof-of-concepts.

None of the three new families carry assigned CVE identifiers yet, so detection rests on keeping endpoint products current and watching for unexpected privilege escalation chains. The disclosures underscore how quickly third-party security tooling becomes an attack surface, and how thin the window is between a public PoC and weaponization in the wild.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.