A newly disclosed proof of concept (PoC) by HardBreacher suggests a critical local privilege escalation vulnerability in Kaspersky Endpoint Security on Windows 11. However, this claim by researcher MSNightmare remains unverified, with no confirmation or CVE assignment from Kaspersky.
Alleged Vulnerability Details
MSNightmare describes this issue as a zero-day vulnerability that could allow privilege escalation in Kaspersky’s enterprise security software. According to the PoC’s documentation, the exploit was tested on Windows 11 version 25H2 with Kaspersky Endpoint Security version 14.0.0.504, focusing on interactions between local users and Kaspersky’s user-interface processes.
The proof of concept reportedly enables the creation of a DLL file at C:WindowsSystem32MY_SNAKE_IS_SOLID.dll, granting full user permissions. This action, if replicable, might allow low-privileged users to exceed their security boundaries on Windows systems.
Challenges in Exploitation
The repository lacks a comprehensive exploit chain, and the author admits to its instability, frequent errors, and the need for multiple attempts. Additionally, the testing involved system reboots, which underscores the limitations of this PoC. While these factors hinder broad exploitability, the potential impact remains significant, as it could disrupt normal operations of the Kaspersky UI process.
Such disruptions could cause erratic allow-or-block decisions concerning files, potentially destabilizing endpoints. In enterprise settings, where endpoint security software holds significant privileges, a reliable exploit could pose substantial risks.
Implications for Security Teams
Despite the critical nature of privilege-escalation vulnerabilities in security products, the severity of HardBreacher’s claims hinges on reproducibility and specific conditions. Organizations using Kaspersky Endpoint Security should consider these claims as cautionary rather than definitive threats.
It is advisable for security teams to monitor Kaspersky’s official communications for updates or patches and to scrutinize system telemetry for anomalies, particularly concerning Kaspersky processes or unexpected DLL activities in System32. Until official confirmation, testing the PoC on live systems is discouraged due to potential operational disruptions.
Organizations must remain vigilant, leveraging threat intelligence to stay ahead of potential security incidents, while awaiting further validation from Kaspersky regarding these zero-day claims.
