A security researcher who goes by the handle Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare and MSNightmare, published three new zero-day proof-of-concept exploits within a single week, targeting security and driver software from Avast, CrowdStrike and Nvidia.
Three Exploits, Three Vendors
The first, dubbed PrettyPrague, targets the sandbox used by Avast Antivirus to spawn a shell with full system privileges, and the researcher says it may also affect other GenDigital products, including AVG and Norton. A GenDigital spokesperson told SecurityWeek the company was made aware of the issue, initiated its security response procedures, and has fixed it.
The second, FalconFlank, exploits a bug in the Office malicious-macro remediation feature of CrowdStrike Falcon Sensor to escalate privileges. CrowdStrike said it is actively investigating the claims and has advised customers to disable a related Windows policy setting while pointing to guidance in its support portal.
The third, GreenSection, targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode display driver components on Windows. Nvidia said it is reviewing the reported behavior through its established security processes.
Part of a Broader Pattern
Nightmare Eclipse became known for a series of zero-day exploits targeting Microsoft products before expanding to other vendors. In late August, the researcher released a separate privilege-escalation zero-day affecting a Kaspersky endpoint security product, which Kaspersky patched on Aug. 31. Independent security researcher Kevin Beaumont said he had confirmed that the Avast, CrowdStrike and Kaspersky exploits work as described.
None of the three latest exploits are confirmed to grant SYSTEM-level access on their own; each requires local code execution as a starting point and functions as a privilege-escalation primitive rather than a full remote compromise chain. All three vendors said they are investigating or have already issued fixes.

Leave a Reply