CHAOTIC Eclipse, a security researcher known for releasing zero-day exploits, has disclosed a new exploit called HardBreacher targeting a privilege escalation flaw in Kaspersky Endpoint Security. This zero-day affects fully patched Windows 11 systems running Kaspersky Endpoint version 14.0.0.504. The exploit is described as unstable, often requiring multiple attempts to succeed, but, if successful, it creates a DLL in the System32 directory, granting full user permissions.
The exploit can disrupt Kaspersky’s UI process, leading to file access issues and potential instability of the operating system. Chaotic Eclipse's past work largely involves Microsoft product exploits, sparking debates on responsible disclosure and the implications of publicly releasing such vulnerabilities.