>samit_hota
Back to security news

Security News · SN-2026-451

HIGHOPEN

Nightmare Eclipse Drops Zero-Day Exploits for CrowdStrike, Nvidia, and Avast

Affected: CrowdStrike Falcon Sensor · Avast Antivirus · AVG · Norton · Nvidia User-Mode Components

Samit Hota·
#news#vulnerability-disclosure#nightmare

Security researcher Nightmare Eclipse—also known online as Chaotic Eclipse, Infinite Nightmare, and MSNightmare—has publicly dropped three new zero-day proof-of-concept (PoC) exploits targeting enterprise and consumer security software and graphics components. The release includes targeted Local Privilege Escalation (LPE) exploits against Avast Antivirus, CrowdStrike Falcon Sensor, and Nvidia driver components, dubbed PrettyPrague, FalconFlank, and GreenSection respectively.

Security researcher Kevin Beaumont has independently verified that the exploits targeting Avast, CrowdStrike, and Kaspersky function as claimed. This public drop follows a similar zero-day release by Nightmare Eclipse in late August, when the researcher published “HardBreacher,” an LPE exploit against Kaspersky endpoint security products that Kaspersky subsequently patched on August 31.

The Exploits: PrettyPrague, FalconFlank, and GreenSection

The three newly dropped exploits target core security boundaries across endpoint protection platforms and hardware components:

  • PrettyPrague (Avast / GenDigital): This PoC targets a privilege escalation flaw within the Avast sandbox environment. By escaping or manipulating the sandbox boundary, an unprivileged user can spawn an interactive shell running under full NT AUTHORITY\SYSTEM privileges. Because GenDigital maintains a shared code architecture across several of its acquired security lines, the vulnerability extends beyond Avast Antivirus to related products, including AVG and Norton.
  • FalconFlank (CrowdStrike Falcon Sensor): This exploit leverages a flaw in how the CrowdStrike Falcon Sensor performs automated remediation on malicious Microsoft Office macros. An attacker with local access can abuse this remediation logic to escalate privileges to SYSTEM.
  • GreenSection (Nvidia): GreenSection exploits an out-of-bounds (OOB) memory write flaw in a shared global memory section utilized by multiple user-mode Nvidia graphics components. While Nightmare Eclipse noted that this specific PoC does not immediately yield direct SYSTEM access out of the box, it reliably crosses user-to-user boundaries and can be leveraged to hijack or compromise the Windows Desktop Window Manager process (dwm.exe).

Understanding the Attack Surface and Vulnerability Classes

Security tools like CrowdStrike Falcon Sensor, Avast, AVG, and Norton represent high-value targets for local privilege escalation because they necessarily operate at the highest privilege levels on an operating system. To perform deep packet inspection, memory monitoring, process injection blocking, and file remediation, endpoint detection and response (EDR) software and antivirus agents run as kernel drivers or high-integrity Windows services running as SYSTEM.

When security software exposes insecure inter-process communication (IPC) channels, flaws in sandbox isolation, or race conditions during automated file remediation, an attacker who has already obtained low-privilege access on an endpoint can trick the security agent into acting on their behalf. In the case of FalconFlank, abusing file remediation logic—where a security tool deletes, moves, or alters files on disk with high privileges—is a classic arbitrary file write or privilege escalation vector.

For GreenSection, shared memory sections created by graphics drivers across user-mode processes often suffer from missing access control lists (ACLs) or insufficient bounds checking. An out-of-bounds write in shared global memory allows a standard user process to corrupt memory structures read by higher-integrity processes or other user sessions, leading to process hijacking or code execution in the context of system services like dwm.exe.

Impact and Blast Radius

Local privilege escalation zero-days present severe operational risks to enterprise environments. In a typical attack chain, threat actors gain initial access through phishing, compromised credentials, or web vulnerabilities, landing as a low-privileged standard user or service account. Exploits like FalconFlank or PrettyPrague allow attackers to instantly bypass internal privilege boundaries, dump credentials from memory (such as LSASS), disable host-based controls, establish persistence, and begin lateral movement across the internal network.

Because CrowdStrike Falcon is widely deployed across enterprise fleets, an unpatched privilege escalation flaw in the endpoint sensor creates an immediate surface for internal privilege escalation across millions of corporate endpoints. On consumer and small-business endpoints, zero-days in Avast, AVG, and Norton give local malware or malicious scripts standard access to full device takeover.

Vendor Response and Remediation Guidance

Remediation steps vary by vendor across the three impacted products:

GenDigital (Avast, AVG, Norton)

GenDigital confirmed it was made aware of the issue affecting Avast Antivirus and related products, initiated its security response procedures, and pushed a fix. Organizations and consumer users should ensure their Avast, AVG, and Norton desktop clients are fully updated to the latest build version via automatic updates.

CrowdStrike

CrowdStrike is actively investigating FalconFlank and has issued a dedicated Tech Alert within the CrowdStrike support portal. To mitigate the privilege escalation vector, CrowdStrike advises enterprise administrators to perform the following policy modification immediately:

  1. Open the CrowdStrike Falcon Management Console.
  2. Disable the Microsoft Office File Suspicious Macro Removal Windows policy setting.
  3. Ensure that Cloud Anti-malware for Microsoft Office Files settings remain enabled to maintain detection and prevention coverage against macro-based threats without exposing the remediation trigger.

Nvidia

Nvidia has been notified of the GreenSection out-of-bounds memory write issue. Pending a formal security bulletin and driver patch release from Nvidia, security teams should restrict local interactive user access on systems hosting shared graphics resources, such as virtual desktop infrastructure (VDI) servers, and monitor for unusual process injection or crash events involving dwm.exe.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call