A cybersecurity researcher known as Nightmare Eclipse has disclosed zero-day vulnerabilities affecting prominent software vendors, including Avast, CrowdStrike, and Nvidia. These newly revealed exploits have raised concerns within the cybersecurity community.
Background on Nightmare Eclipse’s Activities
Nightmare Eclipse, also identified by aliases such as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, initially gained attention for exploiting Microsoft’s products. Recently, the researcher has shifted focus to uncovering vulnerabilities in other major vendors.
In late August, Nightmare Eclipse published a zero-day exploit named HardBreacher, targeting Kaspersky’s endpoint security product. Kaspersky addressed this vulnerability with a patch released on August 31.
Details of the New Exploits
Within a brief period last week, three more zero-day exploits were unveiled by Nightmare Eclipse. These are known as PrettyPrague, FalconFlank, and GreenSection.
The PrettyPrague exploit specifically targets Avast’s sandbox, allowing attackers to gain elevated system privileges. According to the researcher, this vulnerability could potentially impact other GenDigital products, such as AVG and Norton. GenDigital has acknowledged this issue and confirmed its resolution.
Impact on CrowdStrike and Nvidia
The FalconFlank exploit affects CrowdStrike’s Falcon Sensor by exploiting a flaw in the Office malicious macros remediation feature, leading to privilege escalation. CrowdStrike recommends disabling certain Microsoft Office policies to mitigate risk and advises customers to refer to the FalconFlank Tech Alert for updates.
Regarding Nvidia, the GreenSection exploit targets a memory write vulnerability within Nvidia’s user-mode components. This flaw may not grant SYSTEM privileges immediately but poses a threat across user boundaries. Nightmare Eclipse expressed interest in further developments on this exploit.
Industry Reactions and Future Outlook
Security expert Kevin Beaumont has confirmed the functionality of the exploits affecting Avast, CrowdStrike, and Kaspersky. As the cybersecurity landscape evolves, vendors must remain vigilant in identifying and patching vulnerabilities swiftly.
Nvidia has yet to respond to inquiries about the GreenSection exploit. The continuous discovery of such vulnerabilities underscores the importance of proactive security measures and regular software updates to protect users against potential threats.
