HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11
ID: 00e1da16-de04-5d58-9084-cdf9977bbe49
STIX ID: report--00e1da16-de04-5d58-9084-cdf9977bbe49
Feed Name: cybersecurityNews.com
A public GitHub proof-of-concept (HardBreacher / MSNightmare) claims an unconfirmed local privilege-escalation zero-day in Kaspersky Endpoint Security on Windows 11 (25H2), allegedly allowing a low-privileged user to create a DLL in C:\Windows\System32 and gain elevated access; the PoC is described as unstable, may require multiple attempts and a reboot, and has not been verified or assigned a CVE by Kaspersky, so organizations are advised to monitor vendor advisories, avoid running the code in production, and review telemetry for anomalies involving Kaspersky processes and unexpected System32 modifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
