AI Security AI安全 2h ago Updated 56m ago 更新于 56分钟前 46

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits 噩梦日食发布CrowdStrike、Nvidia、Avast零日漏洞利用

Security researcher Nightmare Eclipse (also known as Chaotic Eclipse/MSNightmare) released three zero-day exploits targeting Avast, CrowdStrike, and Nvidia products in rapid succession PrettyPrague targets the Avast sandbox for privilege escalation and may also affect other GenDigital products including AVG and Norton; GenDigital has since patched the vulnerability FalconFlank exploits a bug in CrowdStrike Falcon Sensor's Office malicious macros remediation feature for privilege escalation; Crow 安全研究员Nightmare Eclipse(又名Chaotic Eclipse)在短期内连续发布三个零日漏洞利用代码:PrettyPrague(Avast)、FalconFlank(CrowdStrike)和GreenSection(Nvidia) PrettyPrague可针对Avast沙箱实现完全系统权限提权,可能影响GenDigital旗下AVG、Norton等产品 FalconFlank利用CrowdStrike Falcon Sensor的Office恶意宏修复功能中的缺陷实现提权 GreenSection针对Nvidia用户模式组件的共享全局内存区域进行越界内存写入,可跨用户边界

72
Hot 热度
62
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • Security researcher Nightmare Eclipse (also known as Chaotic Eclipse/MSNightmare) released three zero-day exploits targeting Avast, CrowdStrike, and Nvidia products in rapid succession
  • PrettyPrague targets the Avast sandbox for privilege escalation and may also affect other GenDigital products including AVG and Norton; GenDigital has since patched the vulnerability
  • FalconFlank exploits a bug in CrowdStrike Falcon Sensor's Office malicious macros remediation feature for privilege escalation; CrowdStrike advises disabling the suspicious macro removal policy as a workaround
  • GreenSection targets an out-of-bounds memory write in a shared global memory section used by multiple Nvidia user-mode components, potentially enabling cross-user boundary exploitation or compromising dwm.exe
  • Independent security researcher Kevin Beaumont confirmed that the Avast, CrowdStrike, and prior Kaspersky (HardBreacher) exploits are functional

Why It Matters

This incident highlights the growing trend of a single threat actor systematically targeting multiple major cybersecurity vendors, exposing vulnerabilities in products designed to protect against exactly these kinds of attacks. For AI and security practitioners, it underscores the critical importance of defense-in-depth strategies, as even endpoint protection tools can become vectors for privilege escalation when compromised.

Technical Details

  • PrettyPrague: Exploits a vulnerability in Avast's sandboxing mechanism to spawn a shell with full system privileges; the flaw may extend to other GenDigital-branded products (AVG, Norton). GenDigital confirmed and patched the issue.
  • FalconFlank: Targets a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor, enabling privilege escalation. CrowdStrike recommends disabling the "Microsoft Office File Suspicious Macro Removal" Windows policy setting as an interim mitigation, noting that Cloud Anti-malware for Microsoft Office Files settings continue to provide protection.
  • GreenSection: Involves an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. While it does not immediately yield SYSTEM privileges, it can be leveraged for cross-user boundary exploitation or to compromise the dwm.exe (Desktop Window Manager) process.
  • HardBreacher (prior exploit): A privilege escalation zero-day in Kaspersky endpoint security, patched on August 31.
  • All three new exploits were released within a short time window, and their functional validity was independently confirmed by security researcher Kevin Beaumont.

Industry Insight

  • The rapid succession of zero-days across major security vendors suggests either a coordinated research effort or a single actor with deep expertise in endpoint and driver-level vulnerabilities; organizations should prioritize patching and monitor for related exploit activity.
  • The CrowdStrike workaround of disabling a security policy feature highlights the inherent tension between defense mechanisms and exploit surface — vendors should review whether remediation features introduce new attack vectors.
  • The Nvidia GreenSection exploit's potential to compromise dwm.exe indicates that GPU driver vulnerabilities can have broader system-level implications beyond graphics processing, warranting closer scrutiny of user-mode driver security across all hardware vendors.

TL;DR

  • 安全研究员Nightmare Eclipse(又名Chaotic Eclipse)在短期内连续发布三个零日漏洞利用代码:PrettyPrague(Avast)、FalconFlank(CrowdStrike)和GreenSection(Nvidia)
  • PrettyPrague可针对Avast沙箱实现完全系统权限提权,可能影响GenDigital旗下AVG、Norton等产品
  • FalconFlank利用CrowdStrike Falcon Sensor的Office恶意宏修复功能中的缺陷实现提权
  • GreenSection针对Nvidia用户模式组件的共享全局内存区域进行越界内存写入,可跨用户边界利用
  • 安全研究员Kevin Beaumont确认Avast、CrowdStrike和Kaspersky的漏洞利用代码有效

为什么值得看

本文揭示了当前主流安全软件(Avast、CrowdStrike、Kaspersky)和硬件厂商(Nvidia)产品中存在的关键安全漏洞,对依赖这些产品的企业用户和网络安全从业者具有重要警示意义。同时展示了零日漏洞研究从微软产品向其他厂商扩展的新趋势,反映了安全研究领域的动态变化。

技术解析

  • PrettyPrague漏洞:针对Avast沙箱环境的提权漏洞,攻击者可通过该漏洞获取完全系统权限。GenDigital已确认漏洞并修复,建议用户更新产品。该漏洞可能影响GenDigital旗下其他产品如AVG和Norton。
  • FalconFlank漏洞:利用CrowdStrike Falcon Sensor中Office恶意宏修复功能的缺陷实现提权。CrowdStrike建议客户禁用"Microsoft Office File Suspicious Macro Removal Windows"策略设置,但Cloud Anti-malware for Microsoft Office Files设置仍提供保护。
  • GreenSection漏洞:针对Nvidia用户模式组件的越界内存写入漏洞,影响多个Nvidia组件共享的全局内存区域。该漏洞不能直接获取SYSTEM权限,但可轻松实现跨用户边界利用或 compromise dwm.exe进程。
  • HardBreacher漏洞:此前Nightmare Eclipse发布的针对Kaspersky终端安全产品的提权漏洞,Kaspersky已于8月31日修复。

行业启示

  • 安全软件本身的安全风险:主流安全产品(杀毒软件、EDR)因拥有高权限运行,一旦存在漏洞将被攻击者利用获得系统控制权,企业需建立安全软件自身的漏洞管理和应急响应机制。
  • 零日漏洞研究多元化趋势:知名漏洞研究员从专注微软产品扩展到安全软件和硬件厂商,表明零日漏洞研究市场正在多元化,厂商需关注非传统攻击面的安全加固。
  • 快速响应与补丁管理的重要性:从漏洞披露到厂商响应的时间窗口至关重要,企业应建立及时的漏洞情报监控和补丁更新流程,降低零日漏洞利用风险。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究