Nightmare Eclipse Publishes PoCs for Avast Sandbox Escape, CrowdStrike Macro Remediation Flaw, and Nvidia Shared Memory OOB Write
A single researcher published three working PoCs against major endpoint and hardware vendors in rapid succession. Official mitigations remain partial while the pattern of targeting security software itself continues. Independent confirmation exists for at least two exploits.
The researcher published PrettyPrague, FalconFlank, and GreenSection within days. PrettyPrague achieves SYSTEM from the Avast sandbox and may affect GenDigital siblings. FalconFlank bypasses CrowdStrike's malicious macro removal policy. GreenSection is an out-of-bounds write in a shared section usable for cross-user or dwm.exe compromise. Kevin Beaumont confirmed the first two function as described.
Vendor statements reveal uneven readiness. GenDigital issued a fix. CrowdStrike directed customers to disable a specific policy while relying on cloud AV. Nvidia stated it is reviewing improper access controls on the shared section. These responses follow the researcher's August Kaspersky HardBreacher disclosure, patched in four days.
The sequence shows deliberate targeting of endpoint protection and graphics components that sit below user processes. Shared memory sections and macro remediation paths have received less external scrutiny than kernel drivers. Exploitation chains could start from low-privilege contexts and reach protected processes without triggering standard EDR telemetry.
Patches are expected within weeks. Community development of full chains from the Nvidia primitive is likely. Endpoint vendors will face renewed pressure to harden sandbox boundaries and shared sections used by user-mode components.
CrowdStrike: Public FalconFlank patch or policy default change issued within 21 days.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/)
- [2]Supporting Source(https://twitter.com/GossiTheDog)