HardBreacher PoC Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
Brief
A publicly available proof-of-concept (PoC) named HardBreacher claims to exploit an unpatched elevation-of-privilege issue in Kaspersky Endpoint Security for Windows, potentially allowing a local user to gain high-level access on affected Windows 11 systems.
Documented by GitHub user MSNightmare, also known as Nightmare Eclipse, and should be treated as an unverified but high-priority enterprise security exposure pending vendor confirmation.
The HardBreacher repository describes the issue as a “Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability.”
HardBreacher PoC Targets Kaspersky Endpoint Security Zero-Day
According to the project documentation, the researcher tested the PoC against a fully patched Windows 11 25H2 environment running Kaspersky for Endpoint version 14.
- 0.
- The claimed weakness is local rather than remote.
