Security News Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,119
6,100
2,168
Germany
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.
The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia.

Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well.

In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31.

Within a short window last week, Nightmare Eclipse dropped three new zero-day exploits, dubbed PrettyPrague, FalconFlank, and GreenSection.

The PrettyPrague proof-of-concept (PoC) code, the researcher says, targets the Avast sandbox to spawn a shell with full system privileges, and may also affect other GenDigital products, including AVG and Norton.

“Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges. We immediately initiated our security response procedures and have fixed the issue. We take all security matters seriously and encourage users to keep their products up to date to ensure they are protected,” a GenDigital spokesperson said, responding to a SecurityWeek inquiry.
FalconFlank exploits a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor for privilege escalation, the researcher says.

“We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal,” CrowdStrike told SecurityWeek.

The GreenSection exploit, Nightmare Eclipse says, targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components.

“While this bug does not get SYSTEM privileges immediately, it can be used cross user to user boundary easily or even compromise the dwm.exe process. I didn’t look deeply into it, but I’d be happy to see someone making a full exploit out of it,” Nightmare Eclipse notes.

“We are aware of reports describing a proof-of-concept that demonstrates improper access controls on a shared memory section used by certain NVIDIA GPU display driver components on Windows. NVIDIA is reviewing the reported behavior through our established security and product engineering processes. NVIDIA takes reports of this nature seriously and is actively investigating to determine the root cause, affected configurations, and appropriate remediation,” an Nvidia spokesperson said.

Security researcher Kevin Beaumont said late last week that the Avast, CrowdStrike, and Kaspersky exploits work.
 


Hi, this is worth taking seriously, but the headline compresses three different situations into one. The Avast issue reportedly had corrected versions available by September 4; CrowdStrike supplied a specific temporary policy mitigation; NVIDIA was still investigating the affected configurations and remediation. These are local privilege or boundary-crossing flaws, not evidence that merely having one of the products installed automatically compromises a PC.

What the reports actually establish​

The PrettyPrague PoC reportedly targets the Avast sandbox and can spawn a shell with SYSTEM privileges. Gen Digital confirmed a flaw and reportedly issued corrected versions on September 4. Whether every AVG or Norton configuration was affected is not established by the supplied evidence.

FalconFlank concerns CrowdStrike Falcon Sensor's Microsoft Office malicious-macro remediation feature. The quoted vendor response advises customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while retaining protection through Cloud Anti-malware for Microsoft Office Files.

GreenSection concerns insufficient access controls and an out-of-bounds write involving shared memory used by certain NVIDIA Windows display-driver components. NVIDIA was investigating the root cause, affected configurations and mitigation. The available material does not establish that this PoC directly obtains SYSTEM privileges; reports instead describe possible cross-user impact, DWM compromise or memory corruption. So grouping all three as equivalent SYSTEM-level exploits is a little too tidy for the evidence. [1] [2]

Practical action​

  1. Avast users: update the application and virus definitions, then confirm the program reports no pending update. The corrected-version report does not provide exact version numbers, so it is not possible here to identify a precise fixed build. Do not assume AVG or Norton is affected solely because those names appeared in the report.
  2. CrowdStrike environments: administrators should follow the FalconFlank Tech Alert in the authenticated support portal and apply CrowdStrike's stated policy workaround. On a managed device, users should not alter Falcon policies themselves; pass the alert to the security or IT team.
  3. NVIDIA users: install current signed display-driver updates when NVIDIA publishes them through its official channels. Since affected versions and a confirmed fix are absent from the supplied material, replacing drivers repeatedly or removing the GPU software would be premature.

Privilege-escalation exploits generally require an attacker to obtain some ability to run code or otherwise access the machine first. They are valuable for turning limited access into more powerful access, but they are not usually a magic remote-compromise button. Updating promptly and limiting untrusted execution remain the useful responses; panic-uninstalling security software does not. [1] [2]

Sources
  1. Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits - SecurityWeek
  2. Nightmare Eclipse: PoCs Targeting NVIDIA, CrowdStrike, and Avast
 
Here we go again, nightmare releasing more POC's. And this security researrcher is definitely not on our side,

" I’d be happy to see someone making a full exploit out of it, ”

I think the most feared fears of adversary AI has come to fruit. He is definitely using a non-guardrailed AI. He released a POC just last week, and a few more previously in short succession. Nobody can gain familiarity with such different products so quickly. And he's not on our side. And he is setting a bad example. What do we do now?

I think instead of relying on Trump to talk to the Chinese leader, we should instead put our CIA/CSIS assassins to work ? ( Watched too many movies = me ) :)
 
Last edited:
I think instead of relying on Trump to talk to the Chinese leader
I was a bit perplexed by the Chinese reference, so I searched. The current rumor seems to be that the researcher is a former Microsoft employee who worked there between September 2022 and June 2025. The rumor also mentioned that they may be based in Germany, preventing Microsoft's legal threat from coming to full fruition because of its labor laws.