HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
ID: fc546381-0c15-56c5-a0e6-460e8e4c6148
STIX ID: report--fc546381-0c15-56c5-a0e6-460e8e4c6148
Feed Name: GBHackers
The report details a proof-of-concept called HardBreacher that allegedly exploits a local privilege escalation in Kaspersky Endpoint Security (tested by the author on Windows 11 with Kaspersky for Endpoint v14.0.0.504) to create a DLL in C:\Windows\System32 and elevate to SYSTEM. The PoC is unconfirmed by Kaspersky and described as unreliable, requires local code execution, and organizations are advised to inventory affected endpoints, avoid running the PoC in production, enforce least privilege, monitor for anomalous DLL creation and Kaspersky process activity, and await vendor advisories or fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
