ZeroHour
Security Affairspublished ()ingested Pierluigi Paganini
Part of a story covered by 2 sources: “Researcher Chaotic Eclipse Unleashes Zero-Day PoC Wave: ShieldCrash Defender Patch Bypass, NVIDIA GreenSection, CrowdStrike FalconFlank” — merged summary and timeline →

Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day

mediumExploit / PoCimportance 52
AI summary · glm-5.3-flash

Researcher Chaotic Eclipse released GreenSection, a PoC exploiting an unpatched out-of-bounds write in NVIDIA Windows user-mode shared memory.

Security researcher Chaotic Eclipse disclosed an out-of-bounds write in NVIDIA's Windows user-mode components, which share a global memory section (\BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba}) with full read/write access to all users. The PoC crashes applications running Vulkan or OpenGL; the researcher says the bug could cross user boundaries or compromise dwm.exe but did not fully assess the impact. No CVE has been assigned and no patch is mentioned. The researcher recently released zero-day PoCs against Kaspersky, Avast, and CrowdStrike Falcon.

  • NVIDIA user-mode components share a global memory section with full read/write access
  • Reused data from the shared section causes out-of-bounds memory writes
  • PoC crashes Vulkan or OpenGL applications; potential to compromise dwm.exe
Full article639 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 07, 2026

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia Memory Corruption Zero-Day

Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw.

The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. Several NVIDIA components share a global memory section that gives all users full read/write access. Although the software performs checks to prevent misuse, it reuses data from this shared memory at runtime, which can lead to an out-of-bounds memory write.

The researcher says the flaw does not immediately provide SYSTEM-level privileges, but it could potentially allow an attacker to cross user boundaries or even compromise the Windows Desktop Window Manager (dwm.exe) process. They did not fully investigate the impact but suggested that the bug could potentially support a more complete exploit.

The researcher also provided a simple proof of concept: run an application using Vulkan or OpenGL, launch the PoC, press Enter, and observe the application crash.

“Multiple NVIDIA user mode components shares a global memory section in \BaseNamedObjects\{52813408-3561-4705-820a-2b3b78be92ba} with full R/W access to everyone, this section stores important data structures inside but there are checks at execution times that prevent anything going wrong. Unfortunately the same data from the section are re-used at runtime causing out-of-bound memory write.” reads the announcement. “While this bug does not get SYSTEM privileges immediately but it can be used cross user to user boundary easily or even compromise the dwm.exe process, I didn’t look deeply into it but I’d be happy to see someone making a full exploit out of it.”

Recently, Chaotic Eclipse released exploits targeting other anti-malware and defense solutions.

Chaotic Eclipse released a zero-day exploit targeting Kaspersky Endpoint Security he named HardBreacher, which triggers a privilege escalation flaw. The researcher pointed out that the PoC is unstable and may require repeated attempts, but when successful, it creates a DLL in System32 with full user permissions. The researcher also claims taking control of Kaspersky’s UI process can disrupt the antivirus and interfere with file-access controls, potentially leaving the system in an unstable state.

Nightmare Eclipse says the Kaspersky Endpoint Security zero-day allows privilege escalation on a fully patched Windows 11 25H2 system running Kaspersky Endpoint v14.0.0.504.

The researcher also released a zero-day exploit targeting GenDigital Avast Antivirus, named PrettyPrague. The exploit triggers a privilege escalation flaw.

The researcher claims to have found another zero-day in an antimalware product, this time targeting Avast Antivirus. The PoC exploits a flaw in Avast Sandbox to dump the Windows SAM database and gain a SYSTEM-level shell. It reportedly works even on fully patched Avast Antivirus and Windows 11 25H2. The researcher also suspects the flaw may affect other Gen Digital products, including AVG and Norton.

Finally, Chaotic Eclipse released a new zero-day exploit targeting Crowdstrike Falcon cybersecurity platform. The researcher named the exploit FalconFlank, it triggers a privilege escalation flaw.

According to the researcher, FalconFlank abuses Falcon’s “Microsoft Office file malicious macro removal” feature. The function is part of Falcon’s remediation capabilities and operates with high privileges. The researcher claims that this behavior can be abused to escalate privileges from a low-privileged local user to a more powerful context.

Chaotic Eclipse, also known as Nightmare Eclipse, is a researcher known for publicly releasing PoC exploits for zero-day vulnerabilities, often after criticizing vendors’ handling of vulnerability reports. His releases have mainly targeted Microsoft products, including Windows and Microsoft Defender, with some later exploited in the wild. Among the most notable are the Undefend and RedSun Defender zero-days.

His work has fueled debate over responsible disclosure and the risks of publishing working exploits.

Update with a statement from CrowdStrike:

“We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” – CrowdStrike spokesperson

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, NVIDIA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/198589/hacking/chaotic-eclipse-released-greensection-a-poc-for-nvidia-memory-corruption-zero-day.html