Nightmare Eclipse Drops Zero-Day Exploits Targeting Avast, CrowdStrike, and Nvidia
A notorious security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. This comes after the researcher gained fame for a series of zero-day exploits targeting Microsoft's products.
The latest batch of exploits includes PrettyPrague, which targets the Avast sandbox to spawn a shell with full system privileges, FalconFlank, which exploits a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor for privilege escalation, and GreenSection, which targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components.
GenDigital, the company behind Avast Antivirus, has confirmed that a vulnerability was found in their product, allowing attackers to elevate system privileges. CrowdStrike is advising customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting to remain protected.