HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11
Brief
HardBreacher’s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or assigned a CVE by Kaspersky.
The project, published by a researcher, MSNightmare, describes the alleged flaw as a zero-day elevation-of-privilege vulnerability in Kaspersky’s enterprise endpoint product.
According to the repository’s README, the proof of concept was tested on Windows 11 version 25H2 with Kaspersky Endpoint Security version 14.
- 0.
- HardBreacher appears to target the interaction between a local user and a Kaspersky user-interface process.
MSNightmare claims that successful exploitation can create a DLL file at C:\Windows\System32\MY_SNAKE_IS_SOLID.dll and grant the current user full permissions on the file.
