ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

highExploit / PoCimportance 62
AI summary · glm-5.3-flash

Researcher Nightmare Eclipse released working zero-day PoCs for Avast, CrowdStrike Falcon, and Nvidia, prompting a Gen patch, CrowdStrike mitigation, and Nvidia investigation.

Security researcher Nightmare Eclipse released three zero-day exploits within a short window: PrettyPrague targeting the Avast sandbox for full system privileges (possibly affecting other GenDigital products including AVG and Norton), FalconFlank exploiting CrowdStrike Falcon Sensor's Office malicious macros remediation feature for privilege escalation, and GreenSection targeting an out-of-bounds memory write in a shared global memory section used by Nvidia user-mode components. GenDigital said it has fixed the Avast issue; CrowdStrike advised disabling the Microsoft Office File Suspicious Macro Removal policy setting; Nvidia said it is actively investigating the PoC. Kevin Beaumont reported that the Avast, CrowdStrike, and Kaspersky exploits work. The researcher previously released the HardBreacher privilege escalation zero-day in Kaspersky endpoint security, patched August 31.

  • PrettyPrague PoC elevates privileges via Avast sandbox; GenDigital has patched it
  • FalconFlank exploits Falcon Sensor's Office macros remediation; mitigation is a policy setting change
  • GreenSection exploits an out-of-bounds write in a shared Nvidia memory section, potentially compromising dwm.exe
  • Follows late-August HardBreacher Kaspersky zero-day, patched August 31
  • Kevin Beaumont says the Avast, CrowdStrike, and Kaspersky exploits work
Full article475 words · extracted from securityweek.com · click to collapse

The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia.

Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well.

In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31.

Within a short window last week, Nightmare Eclipse dropped three new zero-day exploits, dubbed PrettyPrague, FalconFlank, and GreenSection.

The PrettyPrague proof-of-concept (PoC) code, the researcher says, targets the Avast sandbox to spawn a shell with full system privileges, and may also affect other GenDigital products, including AVG and Norton.

“Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges. We immediately initiated our security response procedures and have fixed the issue. We take all security matters seriously and encourage users to keep their products up to date to ensure they are protected,” a GenDigital spokesperson said, responding to a SecurityWeek inquiry.

Advertisement. Scroll to continue reading.

FalconFlank exploits a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor for privilege escalation, the researcher says.

“We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal,” CrowdStrike told SecurityWeek.

The GreenSection exploit, Nightmare Eclipse says, targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components.

“While this bug does not get SYSTEM privileges immediately, it can be used cross user to user boundary easily or even compromise the dwm.exe process. I didn’t look deeply into it, but I’d be happy to see someone making a full exploit out of it,” Nightmare Eclipse notes.

“We are aware of reports describing a proof-of-concept that demonstrates improper access controls on a shared memory section used by certain NVIDIA GPU display driver components on Windows. NVIDIA is reviewing the reported behavior through our established security and product engineering processes. NVIDIA takes reports of this nature seriously and is actively investigating to determine the root cause, affected configurations, and appropriate remediation,” an Nvidia spokesperson said.

Security researcher Kevin Beaumont said late last week that the Avast, CrowdStrike, and Kaspersky exploits work.

*updated with statement from Nvidia

Related: VMware Workstation and Fusion Updates Patch Critical Vulnerability

Related: Google Patches 6th Chrome Zero-Day of 2026

Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/