Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

Summary: The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.

Security researcher Nightmare Eclipse has released three new zero-day proof-of-concept exploits targeting products from CrowdStrike, Nvidia and Avast. Named FalconFlank, GreenSection and PrettyPrague, the exploits target different components but share a common objective: crossing security boundaries or increasing an attacker’s privileges on Windows systems.

Nightmare Eclipse, also known by names including Chaotic Eclipse, Infinite Nightmare and MSNightmare, previously gained attention through zero-day research involving Microsoft products. The researcher has recently expanded that focus to security and hardware vendors, particularly software operating with elevated privileges or deep integration with Windows.

The disclosures follow HardBreacher, an exploit targeting Kaspersky Endpoint Security that was released in late August. Kaspersky issued a patch on August 31, and the rapid appearance of three additional exploits has increased attention around Nightmare Eclipse’s research into privileged software.

PrettyPrague targets the sandbox used by Avast Antivirus. According to Nightmare Eclipse, successful exploitation allows an attacker to escape the security boundary and launch a command shell with SYSTEM privileges, providing one of the highest levels of access available on Windows.

The vulnerability may extend beyond Avast because several products share technology under parent company Gen Digital. Nightmare Eclipse suggested that AVG and Norton could also be affected, although exposure may depend on the specific components and versions installed.

Gen Digital confirmed that it had been informed about a vulnerability affecting a subset of its products, including Avast Antivirus. The company said the flaw could enable privilege escalation and that the issue has now been fixed, making installation of the latest updates the primary recommendation for customers.

Vulnerabilities in antivirus products can be particularly significant because security software requires extensive operating-system privileges. Endpoint protection tools inspect processes, files, memory and other sensitive resources, meaning a flaw in one of their privileged components could potentially help an attacker gain deeper control of a compromised machine.

FalconFlank, meanwhile, targets CrowdStrike Falcon Sensor. According to Nightmare Eclipse, the vulnerability is associated with functionality used to remediate malicious Microsoft Office macros and can be abused to escalate privileges.

CrowdStrike confirmed that it is investigating the research and provided temporary mitigation guidance. The company advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while the investigation continues, noting that Cloud Anti-malware for Microsoft Office Files can continue providing protection.

The recommendation disables the functionality associated with the reported vulnerability rather than eliminating Office malware protection entirely. CrowdStrike has also published a technical alert for FalconFlank through its customer support portal.

The vulnerability is particularly relevant because EDR agents operate with significant privileges. An attacker who has already gained limited access to a machine could potentially use a privilege-escalation flaw in a trusted security component to move toward administrative or SYSTEM-level control.

However, the disclosures should not automatically be interpreted as unauthenticated remote compromises. Local privilege-escalation vulnerabilities typically require an attacker to already have some ability to execute code on the affected system, meaning they are often used as one stage of a larger attack chain.

Such vulnerabilities remain extremely valuable to attackers. Malware delivered through phishing, malicious downloads or another exploit may initially execute with ordinary user permissions, after which attackers search for additional weaknesses capable of giving them administrative control.

The third exploit, GreenSection, targets Nvidia software and involves an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. Nightmare Eclipse said the flaw does not currently provide immediate SYSTEM privileges but could potentially cross security boundaries between users or compromise Windows Desktop Window Manager (dwm.exe).

GreenSection appears less developed than the Avast and CrowdStrike exploits. Nightmare Eclipse indicated that the vulnerability had not yet been explored deeply enough to produce a complete SYSTEM-level exploitation chain, leaving open the possibility that additional research could increase its practical impact.

SecurityWeek contacted Nvidia regarding the disclosure, but the company had not provided a public response at the time of the report. Details such as exactly which products and versions are affected and whether a security update is being prepared therefore remain unclear.

Independent security researcher Kevin Beaumont said the Avast, CrowdStrike and previously disclosed Kaspersky exploits work, providing external confirmation that the demonstrations represent practical vulnerabilities rather than purely theoretical findings.

The publication of functioning proof-of-concept code increases the urgency surrounding the disclosures. PoCs are useful for defenders and researchers because they demonstrate how vulnerabilities work, but they can also reduce the technical effort required for malicious actors to reproduce an exploit and incorporate it into their own attack chains.

The fact that Avast and CrowdStrike are cybersecurity products makes the findings especially notable. Endpoint security software needs deep access to Windows to detect malware, monitor processes and remediate threats, but those same privileges mean vulnerabilities inside security agents can become attractive targets.

This does not mean organizations should remove endpoint protection software. Instead, security products should themselves be included in vulnerability-management programs and updated with the same urgency applied to operating systems, browsers and other critical applications.

The vendors are currently at different stages of responding. Gen Digital says the Avast vulnerability has been fixed, CrowdStrike is investigating FalconFlank while offering a temporary mitigation, and Nvidia had not publicly responded to GreenSection when SecurityWeek published its report.

There is also an important distinction between publicly available exploit code and confirmed attacks. SecurityWeek’s report does not indicate that criminal or state-sponsored groups are currently exploiting PrettyPrague, FalconFlank or GreenSection in real-world intrusions.

Public availability nevertheless changes the risk because attackers no longer necessarily need to independently discover the vulnerabilities. Once technical details and working demonstrations become available, the period between disclosure and potential malicious adoption can become considerably shorter.

CrowdStrike customers should review the company’s FalconFlank guidance and consider the recommended policy change, while Avast users should verify that their products contain Gen Digital’s fix. Nvidia customers should monitor future security advisories and software updates as additional information about GreenSection becomes available.

The rapid sequence of Nightmare Eclipse disclosures highlights how vulnerability management extends beyond Windows itself. Antivirus products, EDR agents, graphics components and other privileged software can all become part of an attack chain when vulnerabilities allow adversaries to cross security boundaries.

For defenders, the priority is determining whether affected products are deployed, applying available fixes or mitigations and watching for evidence of real-world exploitation. Security software remains software, and when it operates with extensive privileges, vulnerabilities inside that defensive layer can become valuable stepping stones for attackers seeking deeper control of Windows systems.

Key facts

  • Proof-of-concept exploits named Nightmare Eclipse have been released
  • The exploits target zero-day vulnerabilities
  • Affected products include those from CrowdStrike, Nvidia, and Avast
  • The exploits allow for privilege escalation
  • Successful exploitation grants System privileges

Why it matters

The public release of exploits targeting security and hardware components from major vendors like CrowdStrike and Nvidia poses a significant risk to enterprise security. It could enable widespread system compromise, demanding urgent patching and heightened vigilance from organizations relying on these critical infrastructure protections.