Cyber Security News

HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11

HardBreacher’s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or assigned a CVE by Kaspersky.

The project, published by a researcher, MSNightmare, describes the alleged flaw as a zero-day elevation-of-privilege vulnerability in Kaspersky’s enterprise endpoint product.

According to the repository’s README, the proof of concept was tested on Windows 11 version 25H2 with Kaspersky Endpoint Security version 14.0.0.504. HardBreacher appears to target the interaction between a local user and a Kaspersky user-interface process.

MSNightmare claims that successful exploitation can create a DLL file at C:\Windows\System32\MY_SNAKE_IS_SOLID.dll and grant the current user full permissions on the file.

Because System32 is normally protected, the result, if reproducible, could indicate that a low-privileged local user can gain access beyond their intended Windows security boundary.

HardBreacher Kaspersky Zero-Day

The repository does not describe a reliable exploit chain in detail. Its author says the proof of concept is unstable, may terminate with errors, and often requires multiple attempts to succeed.

MSNightmare also states that a reboot was involved during testing. Those limitations are important: a public proof of concept can support investigation, but it does not independently establish broad exploitability across all deployments, configurations, or product builds.

Still, the alleged impact is notable. The README claims that gaining control of the targeted Kaspersky UI process can disrupt the security product’s normal operation.

The reporter MSNightmare says this could lead to unexpected allow-or-block decisions involving files and potentially leave the endpoint in an unstable state.

A dependable version of such an exploit could be particularly concerning in enterprise environments, where endpoint security software runs with powerful privileges and has deep access to files, processes, and policy enforcement controls.

Privilege-escalation flaws in security products are high-value targets because they can turn defensive tooling into an attack path.

HardBreacher Exploit (source: GitHub)

An attacker who already has code execution as a standard Windows user may seek elevated privileges to turn off protections, alter security configurations, access protected data, establish persistence, or move laterally.

The actual severity of HardBreacher, however, depends on whether the reported behavior can be reproduced and whether exploitation requires additional local permissions, specific product settings, or user interaction.

Organizations using Kaspersky Endpoint Security should treat the public claim as a potential security signal rather than a confirmed vulnerability.

Security teams should monitor Kaspersky’s advisories and support channels for validation, patches, mitigations, or an official security bulletin.

They should also review telemetry for unusual activity involving Kaspersky processes, unexpected changes in System32, anomalous DLL creation, and security-service failures.

Until vendor confirmation is available, defenders should avoid testing the public code on production endpoints. The repository’s author warns that the proof of concept can destabilize the operating system, creating both operational and security risks during investigation.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago