Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher

Published August 21, 2026

A researcher published working attack code that lets a program already running on a Windows machine grab full system-level control by abusing a flaw in Kaspersky's business antivirus. Kaspersky says it has already fixed the issue.

Report priority
High
Involves
Kaspersky Endpoint Security

What is known

The proof-of-concept exploit interacts with Kaspersky's own protection process until it can plant a new file with full user permissions in the Windows system folder, and separately can seize control of the antivirus's interface process to change what it blocks or allows.

What to do

Check the installed Kaspersky Endpoint Security version in the app's About screen or through Kaspersky Security Center and compare it against 14.0.0.504, the version the researcher tested this against.

Kaspersky says it has already addressed the flaw, so make sure Kaspersky Endpoint Security and its databases are set to update automatically and confirm the client has pulled the latest build through Kaspersky Security Center.

Reported details

The exploit, dubbed HardBreacher by researcher Chaotic Eclipse (aka Nightmare Eclipse), targets a privilege escalation weakness in Kaspersky Endpoint Security v14.0.0.504 on a fully patched Windows 11 25H2 host. The unreliable PoC, when it succeeds, writes a DLL into C:\Windows\System32 with full permissions for the current user. Chaotic Eclipse also says an attacker can hijack Kaspersky's UI process, letting them grant or block file access arbitrarily and destabilize the OS. No CVE identifier was given in the report, and Kaspersky states the issue has already been fixed.

References