The safety researcher referred to as Nightmare Eclipse has dropped three zero-day exploits focusing on merchandise from Avast, CrowdStrike, and Nvidia.
Also referred to as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the safety researcher got here to fame for a collection of zero-day exploits focusing on Microsoft’s merchandise, however has lately moved to different distributors as nicely.
In late August, Nightmare Eclipse launched a privilege escalation zero-day in a Kaspersky endpoint safety product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31.
Inside a brief window final week, Nightmare Eclipse dropped three new zero-day exploits, dubbed PrettyPrague, FalconFlank, and GreenSection.
The PrettyPrague proof-of-concept (PoC) code, the researcher says, targets the Avast sandbox to spawn a shell with full system privileges, and may have an effect on different GenDigital merchandise, together with AVG and Norton.
“Gen was lately made conscious of a safety vulnerability affecting a subset of Gen merchandise, together with Avast Antivirus, that would permit an attacker to raise their system privileges. We instantly initiated our safety response procedures and have fastened the difficulty. We take all safety issues severely and encourage customers to maintain their merchandise updated to make sure they’re protected,” a GenDigital spokesperson mentioned, responding to a SecurityWeek inquiry.
FalconFlank exploits a bug within the Workplace malicious macros remediation characteristic of CrowdStrike Falcon Sensor for privilege escalation, the researcher says.
“We’re actively investigating these claims and advise prospects to disable the Microsoft Workplace File Suspicious Macro Removing Home windows coverage setting. Prospects stay protected by way of the Cloud Anti-malware for Microsoft Workplace Information settings. We refer prospects to the FalconFlank Tech Alert within the CrowdStrike assist portal,” CrowdStrike advised SecurityWeek.
The GreenSection exploit, Nightmare Eclipse says, targets an out-of-bounds reminiscence write affecting a shared world reminiscence part utilized by a number of Nvidia user-mode elements.
“Whereas this bug doesn’t get SYSTEM privileges instantly, it may be used cross person to person boundary simply and even compromise the dwm.exe course of. I didn’t look deeply into it, however I’d be completely happy to see somebody making a full exploit out of it,” Nightmare Eclipse notes.
“We’re conscious of studies describing a proof-of-concept that demonstrates improper entry controls on a shared reminiscence part utilized by sure NVIDIA GPU show driver elements on Home windows. NVIDIA is reviewing the reported conduct by way of our established safety and product engineering processes. NVIDIA takes studies of this nature severely and is actively investigating to find out the foundation trigger, affected configurations, and applicable remediation,” an Nvidia spokesperson mentioned.
Safety researcher Kevin Beaumont mentioned late final week that the Avast, CrowdStrike, and Kaspersky exploits work.
*up to date with assertion from Nvidia
Associated: VMware Workstation and Fusion Updates Patch Vital Vulnerability
Associated: Google Patches sixth Chrome Zero-Day of 2026
Associated: Over 3 Million WordPress Websites Affected by Migration Plugin Vulnerability
Associated: Cisco Warns of Unpatched Safe E mail Flaws, Patches Vital Swap Vulnerabilities









