SECURITY researchers known as Nightmare Eclipse have released three zero-day exploits targeting Avast, CrowdStrike, and Nvidia, all described as privilege-escalation capabilities. The researcher previously gained notoriety for Microsoft-focused zero-days but has since expanded to other vendors. The disclosure follows a recent August report of a privilege-escalation flaw in a Kaspersky endpoint security product, which Kaspersky patched on 31 August.
PrettyPrague targets the Avast sandbox to spawn a shell with full system privileges and may also affect other Gen Digital products, including AVG and Norton. FalconFlank exploits a bug in CrowdStrike Falcon Sensor’s Office macros remediation feature to achieve privilege escalation; CrowdStrike advises customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting and to rely on Cloud Anti-malware for Microsoft Office Files settings.
GreenSection is described as utilising an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components; Nightmare Eclipse notes the bug does not grant SYSTEM privileges immediately but could be leveraged across user boundaries or to compromise dwm[.]exe, with potential for a full exploit by others.
Credible corroboration comes from security researcher Kevin Beaumont, who stated that the Avast, CrowdStrike, and Kaspersky exploits work, and SecurityWeek has sought comment from Nvidia. GenDigital, CrowdStrike, and Nvidia have issued or implied statements, with responses directing users to ensure updates are applied and configurations adjusted where advised.