Researcher Drops 'HardBreacher' Exploit for Kaspersky Security Software
A bug-hunter who has repeatedly embarrassed Microsoft now has Kaspersky in the crosshairs, releasing a proof-of-concept exploit that can hand an attacker near-total control of a Windows machine running Kaspersky Endpoint Security.

Key points
- A researcher using the name Nightmare Eclipse released a working exploit, called HardBreacher, targeting Kaspersky Endpoint Security on or around the weekend of the disclosure.
- The flaw is a privilege-escalation vulnerability, meaning software that runs with low permissions can abuse it to gain near-unlimited control over the operating system.
- Kaspersky says the underlying bug is already fixed and the patch reaches users automatically through the product's regular database update.
- Nightmare Eclipse has previously released exploits for Windows and Microsoft Defender, at least a few of which were later used by criminals in real attacks.
- Users running Kaspersky Endpoint Security should verify their product has received its latest automatic update.
A security researcher who goes by Nightmare Eclipse (also known online as Chaotic Eclipse) released a public exploit over the weekend targeting Kaspersky Endpoint Security, the antivirus and endpoint-protection suite used by businesses around the world. The exploit is named HardBreacher.
The bug at its centre is a privilege-escalation vulnerability. Think of it this way: every program on your computer runs at a certain level of trust, like floors in a building. Most software lives on the ground floor. A privilege-escalation flaw is a hidden staircase that lets a criminal ride all the way to the penthouse, where they can do almost anything.
What can HardBreacher actually do?
According to Nightmare Eclipse, quite a lot. Taking control of Kaspersky's own interface process, the part of the software the user sees and interacts with, causes the security product to "completely lose it," in the researcher's words. An attacker who succeeds can force Kaspersky to stop working, trick it into granting or blocking access to files it should never touch, and, if the exploit runs cleanly, leave "the entire operating system" in a broken state.
The researcher was candid about the exploit's rough edges. "The PoC is not in the best shape at all, it is basically duct taped, I just managed to make it work and that's all," Nightmare Eclipse wrote. A PoC, or proof-of-concept, is a working demonstration that a flaw is real, released to force a fix rather than as a ready-made criminal tool, though criminals have repurposed this researcher's earlier PoCs before.
Should Kaspersky users be worried right now?
Probably not, as long as their software is up to date. Kaspersky told SecurityWeek the underlying bug has been resolved and the fix goes out automatically through the product's routine database update. Users can also trigger that update manually from inside the application if they want confirmation it has landed.
No CVE identifier or CVSS severity score has been published for this flaw at the time of writing, which is itself notable: a fix is already in the wild, but the formal vulnerability record has not yet appeared in the public database.
| Exploit name | Target product | Status |
|---|---|---|
| HardBreacher | Kaspersky Endpoint Security | Patched via automatic update |
| ShieldBreak | Windows (system shell access) | Previously released |
| LegacyHive | Windows (privilege escalation) | Previously released |
Why does this researcher keep releasing exploits publicly?
Nightmare Eclipse began dropping public exploits after growing frustrated with Microsoft's handling of vulnerability reports, a process where researchers privately tell companies about flaws and give them time to fix them before going public. When that process breaks down, some researchers release their findings openly to force action. The risk is real: several earlier releases from this researcher were picked up by criminals and used in actual attacks before patches were applied.
For anyone running Kaspersky Endpoint Security on a business or personal machine, the immediate step is simple: open the application and confirm it has downloaded its latest update. Automatic updates are on by default, but a manual check takes thirty seconds and removes any doubt.



