Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: avast (1 article)Clear

Researcher drops unpatched zero-days that turn Kaspersky and Avast against the system

A researcher known as Chaotic Eclipse, or Nightmare Eclipse, publicly released two unpatched privilege-escalation zero-day exploits targeting security software, without coordinating with the vendors. One, called HardBreacher, targets Kaspersky Endpoint Security and can disrupt the antivirus and its file-access controls while creating a system-level file. The other, PrettyPrague, escapes the Avast sandbox to dump the Windows account database and spawn a SYSTEM-level shell, and reportedly works on fully patched Avast and Windows 11. The researcher suspects it may also affect other Gen Digital products like AVG and Norton. Because there are no CVEs or patches yet, endpoints are exposed, and security tools' high privileges make them valuable targets.

Check
Track these public exploits closely since no patch exists, monitor endpoints for antivirus tampering, unexpected SYSTEM shells, and access to the Windows account database, and press affected vendors for fixes.
Affected
Windows systems running Kaspersky Endpoint Security or Avast and other Gen Digital antivirus products; the released exploits can escalate a local user to SYSTEM, dump credentials, and disable protection, with no patch.
Fix
Watch for these exploits moving from proof-of-concept to real attacks, restrict local access, monitor for credential-database dumping and security-tool interference, apply vendor patches as soon as they ship, and add compensating detection.