HardBreacher PoC Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation

A publicly available proof-of-concept (PoC) named HardBreacher claims to exploit an unpatched elevation-of-privilege issue in Kaspersky Endpoint Security for Windows, potentially allowing a local user to gain high-level access on affected Windows 11 systems.

Documented by GitHub user MSNightmare, also known as Nightmare Eclipse, and should be treated as an unverified but high-priority enterprise security exposure pending vendor confirmation.

The HardBreacher repository describes the issue as a “Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability.”

HardBreacher PoC Targets Kaspersky Endpoint Security Zero-Day

According to the project documentation, the researcher tested the PoC against a fully patched Windows 11 25H2 environment running Kaspersky for Endpoint version 14.0.0.504.

The claimed weakness is local rather than remote. An attacker would first need code execution or an existing foothold on a targeted device, such as through malware, stolen user credentials, a malicious software installer, or abuse of another vulnerability.

If exploitation succeeds, the local user could reportedly gain permissions that are normally unavailable to that account, thereby converting an initial low-privilege compromise into a far more serious system-level incident.

The publication is especially notable because endpoint security products commonly run with extensive operating-system privileges and interact closely with protected files, processes, services, and user-interface components.

A flaw that allows an attacker to interfere with trusted components can undermine the very controls intended to prevent malicious activity.

The researcher characterizes the current PoC as unstable and says it may fail repeatedly before a successful execution. When it works, the PoC reportedly creates a DLL file in the Windows System32 directory and grants the current user broad permissions on that file.

That behavior is significant because protected Windows directories are normally inaccessible to standard users.

Windows System32  (Source: MSNightmare)
Windows System32 (Source: MSNightmare)

An attacker who can modify or replace content in a system-trusted location may be able to chain the access into persistence, defense evasion, or further privilege abuse, depending on how the affected endpoint components load or interact with the file.

The HardBreacher documentation also claims that controlling the product’s UI process can cause Kaspersky Endpoint Security to behave unpredictably.

The researcher alleges this could lead to security functions failing, file access being incorrectly allowed or denied, and broader operating-system instability. These technical claims have not been independently validated by Kaspersky in material reviewed for this report.

The PoC’s public availability raises the operational urgency for organizations using the cited Kaspersky Endpoint Security release.

Even though the exploit is reportedly unreliable, unstable exploit code can still provide attackers with a starting point for refinement, reliability improvements, or incorporation into post-compromise toolkits.

MSNightmare specifically claims successful testing on a fully patched Windows 11 25H2 deployment, which suggests the alleged vulnerable component resides in the endpoint product rather than the Windows operating system.

The affected Kaspersky Endpoint Security for Windows 14.0.0.504 release was reportedly published on April 16, 2026, with full support scheduled through April 2028.

Organizations should immediately inventory Kaspersky Endpoint Security for Windows deployments, identify systems running version 14.0.0.504, and monitor Kaspersky’s advisories and product update channels for a formal response or a patched build.

Until Kaspersky issues a verified advisory, defenders should treat HardBreacher as a publicly claimed local privilege-escalation risk requiring heightened monitoring rather than a confirmed CVE-backed vulnerability.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories