Overview of Recent Zero-Day Disclosures
The security researcher known as Nightmare Eclipse (also tracked as Chaotic Eclipse, Infinite Nightmare, and MSNightmare) has released three new zero-day exploits targeting major software vendors, as reported by SecurityWeek. Known previously for targeting Microsoft products and a recent Kaspersky privilege escalation flaw dubbed HardBreacher, the researcher has now turned attention toward Avast, CrowdStrike, and Nvidia. Security researchers, including Kevin Beaumont, have verified that the released exploit concepts function as described.
Technical Details of the Exploits
The three disclosed proof-of-concept exploits cover distinct components across endpoint security and hardware vendor software:
- PrettyPrague: Targets the Avast sandbox environment, allowing an attacker to spawn a command shell with full system privileges. The flaw may also impact broader GenDigital product lines, including AVG and Norton offerings. GenDigital acknowledged the issue and stated that response procedures were initiated to address the privilege escalation vector.
- FalconFlank: Focuses on the CrowdStrike Falcon Sensor, specifically targeting a vulnerability within the Office malicious macros remediation feature. CrowdStrike advised customers to investigate the claims and recommended adjusting specific Windows policy settings while maintaining protection through cloud anti-malware configurations.
- GreenSection: Targets an out-of-bounds memory write affecting a shared global memory section utilized across multiple Nvidia user-mode components. While initial execution does not grant immediate high-level system privileges, the flaw facilitates cross-user boundary traversal or potential compromise of the
dwm.exeprocess.
Actionable Recommendations for Defenders
Security teams managing affected endpoints must prioritize immediate containment and mitigation steps:
- Apply Vendor Updates: Ensure all Avast and GenDigital installations are updated to the latest available software versions containing fixes for the sandbox privilege escalation vector.
- Adjust Policy Settings: CrowdStrike users should review the FalconFlank Tech Alert via the vendor support portal and consider disabling the Microsoft Office File Suspicious Macro Removal Windows policy setting while relying on cloud-based anti-malware controls.
- Monitor Nvidia Components: Review system configurations for Nvidia user-mode components and apply subsequent vendor patches as official advisories and remediation guidelines become available.
Related: Bypassing Windows Administrator Protection: Security Research, Nightmare Eclipse Releases HardBreacher Kaspersky Exploit