news.mlab.sh
Back to the feed
vulnerability

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

High
Summary

A security researcher known as Nightmare Eclipse has released three new zero-day exploits targeting Avast, CrowdStrike, and Nvidia. These exploits allow for privilege escalation and could lead to significant security breaches. The researcher has a history of targeting Microsoft products, and these new vulnerabilities highlight the ongoing need for vigilance and timely patching.

A security researcher, known as Nightmare Eclipse and also operating under the aliases Chaotic Eclipse, Infinite Nightmare, and MSNightmare, has released three new zero-day exploits targeting Avast, CrowdStrike, and Nvidia. The researcher is known for targeting Microsoft products, and this recent activity underscores the importance of proactive security measures.

Within a short window last week, Nightmare Eclipse dropped three new zero-day exploits: PrettyPrague, FalconFlank, and GreenSection. The PrettyPrague exploit targets the Avast sandbox to spawn a shell with full system privileges, and may also affect other GenDigital products, including AVG and Norton. GenDigital responded to the claims, stating they were aware of a vulnerability affecting a subset of Gen products and have implemented a fix, advising users to keep their products updated.

FalconFlank exploits a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor for privilege escalation. CrowdStrike advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting to remain protected through Cloud Anti-malware for Microsoft Office Files settings, referring customers to a FalconFlank Tech Alert in the CrowdStrike support portal.

The GreenSection exploit targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. While this bug doesn't immediately grant SYSTEM privileges, it can be used to cross user boundaries or compromise the dwm.exe process. Nightmare Eclipse noted that he didn't delve deeply into this specific exploit but expressed interest in seeing a full exploit developed.

Security researcher Kevin Beaumont confirmed that the Avast, CrowdStrike, and Kaspersky exploits are functional. SecurityWeek is awaiting a response from Nvidia regarding the GreenSection exploit.

Read the full article at SecurityWeek