One Researcher Just Published Working Hacks Against CrowdStrike, Avast, and Nvidia
A prolific security researcher dropped three new zero-day exploits in a single week, targeting software that millions of people and businesses rely on to stay safe.

Key points
- A researcher known as Nightmare Eclipse published three zero-day exploits, meaning software flaws unknown to the affected vendors, targeting Avast, CrowdStrike, and Nvidia products in one week.
- A fourth exploit, against a Kaspersky security product, was published in late August and patched by Kaspersky on 31 August 2024.
- Two of the new exploits allow privilege escalation, where an attacker who already has a foothold on a computer quietly upgrades their access to full system control.
- GenDigital, which owns Avast, says the Avast flaw is now fixed; CrowdStrike has issued a temporary workaround but not yet a patch.
- Independent researcher Kevin Beaumont confirmed the Avast, CrowdStrike, and Kaspersky exploits work as advertised.
A security researcher who goes by Nightmare Eclipse, and is also tracked under the aliases Chaotic Eclipse, Infinite Nightmare, and MSNightmare, published three working exploit tools last week against products from Avast, CrowdStrike, and Nvidia. Each exploit is a zero-day, meaning it targets a flaw the software maker had not previously discovered or fixed.
The release follows a pattern. Nightmare Eclipse built a reputation targeting Microsoft software, then in late August turned attention to Kaspersky, publishing an exploit dubbed HardBreacher that allowed a low-privileged attacker to silently gain full control of a Windows machine. Kaspersky patched that flaw on 31 August.
What do these three new exploits actually do?
The three tools do different things, but two share the same goal: turning limited access into total control of a machine.
The first, called PrettyPrague, targets the Avast antivirus sandbox, a protected space inside the software where suspicious files are run in isolation. The exploit breaks out of that space and opens a command shell with full system privileges. GenDigital, the parent company that also owns AVG and Norton, told SecurityWeek the flaw may affect several of its products. A company spokesperson said: "We immediately initiated our security response procedures and have fixed the issue. We encourage users to keep their products up to date."
The second, FalconFlank, targets CrowdStrike Falcon Sensor, the widely used endpoint security agent that monitors corporate computers for threats. Specifically, it exploits the feature that detects and removes malicious macros, which are small automated scripts sometimes hidden inside Office documents to run malware. CrowdStrike says it is investigating and has told customers to disable the affected policy setting as a temporary precaution. No patch is available yet.
The third, GreenSection, targets Nvidia graphics drivers. It writes data outside the memory space a program is allowed to touch, a class of flaw known as an out-of-bounds memory write. Nightmare Eclipse says this one does not immediately hand an attacker full system control, but it can be used to cross the boundary between two different user accounts on the same machine, which is still a serious capability. Nvidia had not responded to a request for comment at publication time.
Should people using these products be worried?
For most home users, the immediate risk is low but not zero. These exploits are hardest to use when an attacker cannot already get code running on your machine. The realistic danger is to corporate networks, where attackers often get an initial foothold through phishing emails and then use tools like these to escalate from a standard account to full control.
| Exploit name | Target product | Effect | Status |
|---|---|---|---|
| HardBreacher | Kaspersky Endpoint Security | Full system privilege escalation | Patched 31 August 2024 |
| PrettyPrague | Avast (also AVG, Norton) | Full system privilege escalation | Patched by GenDigital |
| FalconFlank | CrowdStrike Falcon Sensor | Privilege escalation via Office macro feature | Workaround issued, no patch yet |
| GreenSection | Nvidia graphics drivers | Cross-user memory access | No response from Nvidia |
If you run Avast, AVG, or Norton, open the application and check for updates now. CrowdStrike customers should check the FalconFlank Tech Alert in the support portal for the current guidance on disabling the affected Office macro policy setting.



