CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Nightmare Eclipse

actor · actor:nightmare-eclipse single-source

Pseudonymous vulnerability researcher/broker persona (tracked under both names) publicly dropping Windows zero-day proof-of-concepts through 2026, the series includes BlueHammer, RedSun, UnDefend, YellowKey (BitLocker, later CVE-2026-45585), GreenPlasma (CTFMON LPE), MiniPlasma (cldflt.sys), GreatXML (BitLocker/WinRE) and RoguePlanet (Defender TOCTOU), and stating publicly that Microsoft will not engage with their reports.

Aliases: Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare

Coverage
11
8 about it · 3 mentions · first 2026-05-15 → last 2026-10-08
Latest activity
2026-10-08
A Defender bypass that needs no vulnerability: fill the disk during every update and the engine stays up…
Peak priority
high
3 high · 5 notable
Targets
public-sector
sectors: public-sector, technology, energy · regions: europe, switzerland
Sources cited
33
19 hosts
2026-05-1511 appearances2026-10-08

Action items (6)

Do-now tasks recorded on the entries about Nightmare Eclipse, newest first. Check the date before acting on an older one.

  • Confirm every Windows endpoint reports Microsoft Malware Protection Engine 1.1.26080.3 or later; the engine version updates on its own cadence and is not covered by the OS patch level, so check it separately; 1.26070.7 is the last affected build.
    2026-08-12CVE-2026-50656 +1
  • Hunt for C:\\Windows\\System32\\phoneinfo.dll across the Windows estate now; LevelBlue states the file is not expected to exist natively on supported Windows versions, so an instance on a supported build is either this chain or an unrelated planted DLL, and either warrants investigation.
    2026-08-12CVE-2026-50656 +1
  • Confirm every CrowdStrike Falcon sensor and Gen Digital Avast install (including on unmanaged or contractor endpoints) is on the current release now that both vendors are reported to have remediated FalconFlank and PrettyPrague; until that is confirmed, treat any endpoint on an older build as still exposed and keep the "Microsoft Office File Suspicious Macro Removal Windows" Falcon prevention setting disabled as an interim control on unconfirmed hosts.
    2026-09-06CrowdStrike, Gen Digital and Kaspersky have all now…
  • On WSUS-gated, air-gapped, offline or OT-adjacent Windows estates where Defender engine updates are deferred or pinned, verify the installed Malware Protection Engine build is ≥ 1.1.26060.3008 (e.g. via Get-MpComputerStatus AMEngineVersion) rather than assuming auto-update reached it.
    2026-07-09CVE-2026-50656
  • Continue tracking the Nightmare Eclipse zero-day series via NCSC-CH's running advisory: RoguePlanet is now fixed, but the same researcher's series has previously dropped further unpatched Defender/Windows PoCs, so treat NCSC-CH's tracker as the authority for the current fix status of each.
    2026-07-09CVE-2026-50656
1 older action item
  • Compensate for the unpatched Defender LPE (CVE-2026-50656) (§ 4). No patch exists, monitor for MsMpEng.exe spawning cmd.exe/powershell.exe as SYSTEM (Sysmon EID 1 parent-image filter, WEL 4688) and constrain which low-privilege accounts can trigger on-demand scans.
    2026-06-19CVE-2026-50656

Defender insights

What each entry about Nightmare Eclipse tells a defender to do, newest first.

2026-10-08NOTABLEA Defender bypass that needs no vulnerability: fill the disk during every update and the engine stays up, stale

Exposure · triage · detection

2026-08-12HIGHMicrosoft has now shipped an engine fix (1.1.26080.3), and the same researcher claims a partial bypass of it

2026-09-06HIGHCrowdStrike, Gen Digital and Kaspersky have all now remediated one researcher's four security-product PrivEsc PoCs, per LevelBlue's follow-up analysis

Latest update · triage

2026-07-29NOTABLELevelBlue reproduces Nightmare Eclipse's latest Windows PoC on a July-2026-patched build, no CVE, no fix, and the abuse uses only legitimate APIs

Triage

2026-07-09NOTABLEMicrosoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June

Triage

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

uses

exploits

attributed activity

Story timeline

Every entry that names Nightmare Eclipse, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-10-08BigDiskBuster: a roughly 300-line Windows proof of concept keeps Microsoft Defender from updating by claiming all free disk space, with no CVE and no patch
    researchA Defender bypass that needs no vulnerability: fill the disk during every update and the engine stays up, stale
  2. 2026-09-06Chaotic Eclipse turns its zero-day drops on third-party security products: local privilege escalation in CrowdStrike Falcon and Avast, with working proof-of-concept code public; all three vendors have since remediated
    trending-vulnerabilitiesCrowdStrike, Gen Digital and Kaspersky have all now remediated one researcher's four security-product PrivEsc PoCs, per LevelBlue's follow-up analysis
  3. 2026-08-12ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025
    trending-vulnerabilitiesMicrosoft has now shipped an engine fix (1.1.26080.3), and the same researcher claims a partial bypass of it
  4. 2026-07-29LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systems
    researchLevelBlue reproduces Nightmare Eclipse's latest Windows PoC on a July-2026-patched build, no CVE, no fix, and the abuse uses only legitimate APIs
  5. 2026-07-09CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series
    trending-vulnerabilitiesMicrosoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June
  6. 2026-06-19Nightmare/Chaotic Eclipse zero-day wave; the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patch
    trending-vulnerabilities
  7. 2026-06-12"GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition, PoC public, practical severity contested
    mentionactive-threats
  8. 2026-06-11"RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch
    mentionactive-threats
  9. 2026-05-30Nightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop
    trending-vulnerabilitiesNightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation)
  10. 2026-05-19Chaotic Eclipse Windows zero-days; MiniPlasma is third PoC in series; cldflt.sys CfAbortHydration path, claimed re-exploitable CVE-2020-17103 regression
    trending-vulnerabilities
  11. 2026-05-15Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassed
    mentionactive-threats
ATT&CK techniques (18 across 7 tactics)

18 techniques observed across 6 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts
  • ExecutionScheduled Task/Job: Scheduled Task · Native API · Hijack Execution Flow · Hijack Execution Flow: DLL
  • PersistenceScheduled Task/Job: Scheduled Task · Valid Accounts · Modify Registry
  • Privilege EscalationScheduled Task/Job: Scheduled Task · Exploitation for Privilege Escalation · Valid Accounts · Access Token Manipulation: Parent PID Spoofing · Abuse Elevation Control Mechanism · Abuse Elevation Control Mechanism: Bypass User Account Control
  • StealthObfuscated Files or Information: Dynamic API Resolution · Masquerading: Match Legitimate Resource Name or Location · Indicator Removal: File Deletion · Valid Accounts · Access Token Manipulation: Parent PID Spoofing · Exploitation for Stealth · System Binary Proxy Execution · Hide Artifacts: Hidden Files and Directories · Hijack Execution Flow · Hijack Execution Flow: DLL
  • Defense ImpairmentModify Registry · Disable or Modify Tools
  • Credential AccessOS Credential Dumping: Security Account Manager

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

Execution TA0002

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1106Native API×2

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.

Evidence: 2026-10-08/bigdiskbuster-defender-update-starvation-disk-exhaustion-poc · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1574Hijack Execution Flow×1

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×2

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

Persistence TA0003

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

Privilege Escalation TA0004

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1068Exploitation for Privilege Escalation×5

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · 2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed · 2026-05-19/chaotic-eclipse-windows-zero-days-miniplasma-is-third-poc-in · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1134.004Access Token Manipulation: Parent PID Spoofing×1

Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the <code>CreateProcess</code> API call, which supports a parameter that defines the PPID to use. This functionality is used by Windows features such as User Account Control (UAC) to correctly set the PPID after a requested elevated process is spawned by SYSTEM (typically via <code>svchost.exe</code> or <code>consent.exe</code>) rather than the current user context.

Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗

T1548Abuse Elevation Control Mechanism×2

Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control×1

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.

Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗

Stealth TA0005

T1027.007Obfuscated Files or Information: Dynamic API Resolution×1

Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native API functions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1070.004Indicator Removal: File Deletion×1

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1134.004Access Token Manipulation: Parent PID Spoofing×1

Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the <code>CreateProcess</code> API call, which supports a parameter that defines the PPID to use. This functionality is used by Windows features such as User Account Control (UAC) to correctly set the PPID after a requested elevated process is spawned by SYSTEM (typically via <code>svchost.exe</code> or <code>consent.exe</code>) rather than the current user context.

Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗

T1211Exploitation for Stealth×1

Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.

Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗

T1218System Binary Proxy Execution×1

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1564.001Hide Artifacts: Hidden Files and Directories×1

Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (<code>dir /a</code> for Windows and <code>ls –a</code> for Linux and macOS).

Evidence: 2026-10-08/bigdiskbuster-defender-update-starvation-disk-exhaustion-poc · ATT&CK page ↗

T1574Hijack Execution Flow×1

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×2

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

Defense Impairment TA0112

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1685Disable or Modify Tools×2

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-10-08/bigdiskbuster-defender-update-starvation-disk-exhaustion-poc · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

Credential Access TA0006

T1003.002OS Credential Dumping: Security Account Manager×1

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.

Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗

Entries about Nightmare Eclipse (8)

2026-10-08 · view entry permalink →

NOTABLENATOB2

BigDiskBuster: a roughly 300-line Windows proof of concept keeps Microsoft Defender from updating by claiming all free disk space, with no CVE and no patch

LevelBlue SpiderLabs reproduced BigDiskBuster, a proof of concept published on GitHub on 2026-09-19 by the actor known as MSNightmare (Nightmare Eclipse) that needs no vulnerability to keep Microsoft Defender from updating (LevelBlue SpiderLabs, 2026-10-05). It watches the C: volume for Defender update activity and, when an update begins, creates a hidden file whose allocation claims essentially all free space; the update runs out of room and fails, Defender cleans up its staging directory and the tool repeats the process on the next attempt (LevelBlue SpiderLabs, 2026-10-05). The Defender service keeps running and real-time protection stays on; in LevelBlue's lab no alert appeared, and the only visible artifact was a stale security-intelligence version and the generic update error 0x80070643 (LevelBlue SpiderLabs, 2026-10-05). The roughly 300 lines of C++ use no memory corruption or kernel component: a raw handle on the volume device, a file opened relative to that handle, a recursive watch of the volume and an oversized allocation, with the file hidden and deleted on close (LevelBlue SpiderLabs, 2026-10-05). It ran under a standard user account on a default Defender installation (Dark Reading, 2026-10-06).

No CVE, patch or Microsoft advisory exists; a Microsoft spokesperson told Dark Reading that Defender Antivirus includes detections and preventions against the proof of concept and that customers should keep security intelligence and platform updates current (Dark Reading, 2026-10-06). The GitHub repository has been taken down, and Dark Reading notes that the technique could in theory extend the life of malicious tooling already on a machine by withholding new detections (Dark Reading, 2026-10-06). No source reports use in an attack.

Triage: a handle on the volume device alone is low-specificity because svchost, SearchIndexer, dllhost and TiWorker hold the same kind of handle in normal operation; in LevelBlue's tested environment only the Defender service processes and TrustedInstaller legitimately held a handle on MRT.exe (LevelBlue SpiderLabs, 2026-10-05).

At the time of publication, BigDiskBuster has no assigned CVE, available patch, or Microsoft advisory.

LevelBlue SpiderLabs 2026-10-05

a Microsoft spokesperson tells Dark Reading that Microsoft Defender Antivirus includes detections and preventions against the PoC

Dark Reading 2026-10-06

a process holding both of these handles simultaneously has no ordinary reason to exist on a stock Windows endpoint

LevelBlue SpiderLabs 2026-10-05
research08 Oct 04:54Zmulti-sourceOpen finding →

2026-08-12 · view entry permalink →

HIGHCVE-2026-50656 +1updatedNATOB2

ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025

The pseudonymous researcher Nightmare Eclipse published ShieldBreak, a proof-of-concept described as defeating the patch Microsoft shipped five weeks earlier for a Windows Defender privilege-escalation flaw (Cyber Kendra, 2026-08-12). Rapid7 places the drop late on Patch Tuesday itself, continuing what it describes as a pattern of the past few months (Rapid7, 2026-08-11). Rapid7, covering the same release in its Patch Tuesday analysis, records the researcher describing ShieldBreak as a full patch bypass for RoguePlanet (the entry in the same series that Microsoft patched as CVE-2026-50656 in July, a month after its public disclosure) and notes that both are elevation-of-privilege-to-SYSTEM vulnerabilities in Defender (Rapid7, 2026-08-11).

Two claims are what make this worth acting on rather than filing. RoguePlanet was a race condition whose reliability varied sharply between machines (the researcher called it hit or miss in June) while "ShieldBreak is listed with a 100 percent success rate". And where the June exploit did not run on Windows Server because standard users cannot mount ISO images there, ShieldBreak is listed as tested on Windows Server 2025 alongside Windows 11 25H2 and the Canary channel (Cyber Kendra, 2026-08-12). Both of those are the researcher's own claims: Cyber Kendra states that "No patch exists for ShieldBreak, and no vendor has reproduced it publicly yet", and that Microsoft had not commented at publication, both true when written on 2026-08-12 and both since overtaken: Microsoft acknowledged the flaw as CVE-2026-69414 two days later and has since shipped an engine fix (2026-09-13 update below). Treat the reliability figure and the server coverage as unverified until someone reproduces them, but treat the existence of working exploit code as established, because that is what the release consists of.

The target is the Microsoft Malware Protection Engine, the scanner behind Defender, which runs as SYSTEM; RoguePlanet abused improper link resolution before file access to spawn a SYSTEM shell on fully updated machines, was rated Important at CVSS 7.8, and was fixed in engine build 1.1.26060.3008 on 2026-07-09. Analysts who dissected RoguePlanet in June described an attack chain built on NTFS junctions, opportunistic locks and the Windows Error Reporting QueueReporting scheduled task, which Cyber Kendra reads as suggesting ShieldBreak reworks the same plumbing rather than opening a new front (Cyber Kendra, 2026-08-12), that is an inference in the reporting, not a stated finding, and no technical analysis of ShieldBreak itself has been published.

The reason a local privilege-escalation PoC from this particular persona deserves more than a backlog ticket is the track record the same reporting sets out: of the previously disclosed flaws in the series, three, BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091) and UnDefend (CVE-2026-45498), were exploited in real-world intrusions before fixes landed and all three ended up in CISA's Known Exploited Vulnerabilities catalog (Cyber Kendra, 2026-08-12). This is also the second time a fix in this class has fallen: Microsoft hardened Defender's internal file-handling APIs in mid-May and RoguePlanet was rewritten to defeat that.

This paragraph describes the position at disclosure, when no fix existed; Microsoft has since shipped one, see the 2026-09-13 update below, and patch first. At the time, compensating controls rather than patching were the available lever. The one the reporting names as strongest for this bug class is application allowlisting, ThreatLocker found it blocked RoguePlanet by default (Cyber Kendra, 2026-08-12). Detection concepts follow the RoguePlanet chain rather than ShieldBreak's unpublished internals, so they are hypotheses to hunt with rather than confirmed signatures for this variant: in filesystem and process telemetry, reparse-point or junction creation by a standard-user process inside a path the Defender engine subsequently touches, and unexpected execution lineage from the Windows Error Reporting scheduled task, are the observable steps that chain described. Because the escalation ends in a SYSTEM process spawned by an engine that legitimately runs as SYSTEM all day, the parent-process shape alone will not separate this from routine scanning activity; the preceding filesystem manipulation by an unprivileged account is where the discriminator lives.

First version of the Microsoft Malware Protection Engine with this vulnerability addressed

Microsoft Security Response Center 2026-08-14

ShieldCrash does not currently have a separate CVE. Nightmare Eclipse describes the public release as a skeleton PoC that demonstrates privileged file reads. It does not establish arbitrary file writes or SYSTEM-level code execution.

SOCRadar 2026-09-10

ShieldBreak is listed with a 100 percent success rate.

No patch exists for ShieldBreak, and no vendor has reproduced it publicly yet.

Cyber Kendra 2026-08-12

We are working to provide a high quality security update that addresses this vulnerability.

Microsoft Security Response Center 2026-08-14

ShieldBreak is tracked as CVE-2026-69414 by Microsoft

NCSC Switzerland (BACS), Cyber Security Hub 2026-08-17

The LevelBlue OpsCTI and THOR teams reviewed and reproduced the complete ShieldBreak exploitation chain with the August 2026 Patch Tuesday updates installed, confirming the PoC functions as described.

ShieldBreak is best detected through behavioral correlation rather than any single static indicator.

ShieldBreak is fully self-contained and runs to full SYSTEM completion from a standard user account on any fully patched Windows 11 24H2 or Windows Server 2025 system with Windows Defender in its default configuration.

The set of expected MpClient.dll consumers is small. A load by an unrelated process becomes especially significant when followed by runtime resolution of MpManagerOpen, MpScanStart, MpCleanOpen, MpCleanStart, or MpCleanControl.

LevelBlue SpiderLabs 2026-08-19
Updaterun 2026-08-18T0410Z-intelaffected_productscvesevidenceregionssectorssourcesbody

The original entry recorded that no patch existed, no vendor had publicly reproduced the ShieldBreak proof-of-concept, and Microsoft had not commented. Two of those three have changed. Microsoft published an advisory on 2026-08-14 that names the technique directly (the vulnerability is described as an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak") and assigned it CVE-2026-69414 (Microsoft, 2026-08-14). The third has not: on the fix, Microsoft states only that "We are working to provide a high quality security update that addresses this vulnerability."

The vendor's own calibration is the useful part of the delta. Microsoft rates the flaw Important with a CVSS 3.1 base score of 7.8 for a local, low-privilege, no-interaction elevation, records it as publicly disclosed, records exploitation as not detected, and sets its exploitability assessment to "Exploitation More Likely" (Microsoft, 2026-08-14). That combination (publicly available exploit code, a vendor expectation of exploitation, and no update) is the shape that justifies attention outside the normal patch cycle, and it is a materially different footing from a researcher's unverified GitHub claim.

The relay is what brought it into this constituency's field of view. Switzerland's NCSC amended its rolling Nightmare Eclipse advisory on 2026-08-17 to record that "ShieldBreak is tracked as CVE-2026-69414 by Microsoft" (NCSC-CH, 2026-08-17), and CERT-FR issued advisory CERTFR-2026-AVI-1035 the same day, listing the Microsoft Malware Protection Engine among affected systems alongside an unrelated, already-patched PowerShell flaw (CERT-FR, 2026-08-17). CERT-FR's bulletin carries its standard instruction to consult the vendor advisory for fixes; for this CVE that advisory has none to offer, which is worth knowing before an operator treats the bulletin as a patchable item.

Detection, telemetry class first. No new behavioural detail was published with the CVE, so nothing here supersedes what the original entry carried. The durable anchor remains process-creation telemetry with parent lineage: the Malware Protection Engine has no legitimate reason to be the parent of an interactive shell or an unexpected child process, so any such process tree rooted at the engine is the signal irrespective of which variant produced it. Triage: the engine's own remediation work (quarantine, deletion, signature updates) runs inside the service rather than by launching command interpreters, so a shell parented to it does not have a benign counterpart; the discriminator is the parent-child relationship itself, not the child's command line.

Updaterun 2026-08-21T0410Z-intelaffected_productscvesevidencesourcestechniquesbody

This pipeline recorded CVE-2026-69414 three days ago as acknowledged by Microsoft, rated 7.8, publicly disclosed, assessed "Exploitation More Likely", with a security update still being worked on. Two things have changed and neither is a fix.

It works on the current patch level, and that is now independently established. "The LevelBlue OpsCTI and THOR teams reviewed and reproduced the complete ShieldBreak exploitation chain with the August 2026 Patch Tuesday updates installed, confirming the PoC functions as described" (LevelBlue SpiderLabs, 2026-08-19). LevelBlue reports the chain running to SYSTEM from a standard user account on Windows 11 24H2 and Windows Server 2025 with Defender in its default configuration, self-contained and needing no arguments, completing in roughly eight to twelve seconds on an idle system. Queried directly, Microsoft's own record for the CVE shows its most recent revision dated the same day as that report, and the change it describes is the addition of a CWE classification, informational only (MSRC, 2026-08-19), exploitation still recorded as no, the exploitability assessment unchanged, and the temporal metrics still recording proof-of-concept code available with no official fix.

The mechanism, which is the substance of the delta. The prior entry had the identifier and Microsoft's rating but not how the chain works. LevelBlue reconstructs it in seven stages, and the elegant part is that the attacker never writes to System32; Defender does.

The exploit first raises its own process and thread priority to improve its odds in a later race, then registers a fake Cloud Files sync provider rooted at a working directory it creates, and creates a placeholder file so Windows treats it as a cloud-resident object not yet downloaded. Its hydration callback is two-faced by design: the first read returns a benign archive, which is what Defender detects; a later read returns the malicious DLL, which is what ends up on disk. Next it resolves native object-manager routines out of ntdll.dll and builds a shadow namespace containing two conflicting symbolic links under the same name (one pointing at the working directory, one at a transaction-log path) giving it a redirection layer that sits above the filesystem. It then loads Defender's own management library directly and resolves that library's scan and clean functions to open Defender's RPC interface, scan the placeholder through the shadow path, and (once Defender has flagged the bait archive) start Defender's own remediation operation against it. A time-of-check-to-time-of-use race, held open with an exclusive lock on a transaction-log file while the symbolic link is swapped underneath, redirects that remediation so Defender's clean engine writes the attacker's DLL into System32. Execution as SYSTEM then comes from a Windows Error Reporting scheduled task loading that DLL through the error-reporting host process.

LevelBlue also places the disclosing persona in a lineage of prior proof-of-concept releases and notes a functional improvement over the immediately preceding one: where the earlier LegacyHive technique needed a helper-account logon to trigger its final stage, ShieldBreak is fully self-contained.

Triage: LevelBlue's own framing is the right instruction; "ShieldBreak is best detected through behavioral correlation rather than any single static indicator", because every component is a legitimate Windows capability. The highest-value single signal is a module load: Defender's management library being loaded by a process outside the small, stable set of Defender's own binaries, especially when that same process then resolves Defender's scan and clean entry points at runtime. Around it, two more composites: an unapproved process registering a cloud sync root and creating a placeholder, then immediately moving into object-manager and Defender API activity; and a standard-user process taking an exclusive lock on a transaction-log file. Each is weak alone (legitimate sync agents register sync roots, and Defender's own processes load its library all day) so the sequence and the identity of the calling process are what separate them. The final stage is the most conventional: a DLL appearing in System32 followed by the error-reporting scheduled task being run on demand, with the payload cleaned up afterwards.

Updaterun 2026-08-24T0410Z-intelactionscvesevidencetagstechniquesbody

The entry this one updates recorded that Microsoft had acknowledged ShieldBreak as CVE-2026-69414, rated it 7.8, assessed it "Exploitation More Likely", and stated a security update was still being worked on, with no published mechanism and therefore nothing to detect on. LevelBlue SpiderLabs has now published the mechanism and, with it, a hunting package (LevelBlue SpiderLabs, 2026-08-19). That is the whole delta, and at the time it mattered because no fix existed: detection was then the only control a defender had. (Microsoft has since shipped an engine fix, see the 2026-09-13 update below.)

The chain turns Windows Defender's own remediation path into the write primitive. The proof-of-concept registers its working directory as a Cloud Files sync root, self-identifying as a sync provider with a hardcoded provider GUID and creating a placeholder file. It then creates two directories beneath the object manager's \BaseNamedObjects\Restricted\ namespace and, inside them, two conflicting symbolic links both named WD_SCAN, one initially resolving to the working directory holding the placeholder, the other to a path used by the Common Log File System. It opens Defender's interface directly, resolving the management, scanning and clean functions out of MpClient.dll at runtime, and asks Defender to scan the placeholder through a \\.\globalroot\...\WD_SCAN\ path. A background thread watches for the CLFS transaction log that Defender's clean operation creates, and the instant it appears takes an exclusive lock on it, freezing Defender mid-transaction. With the operation held open, the proof-of-concept deletes the shadow WD_SCAN link and recreates it pointing at \??\UNC\127.0.0.1\C$\Windows\System32\phoneinfo.dll, so the already-in-flight path resolves somewhere new without any NTFS junction being involved; it then restarts Cloud Files hydration with the file size set to the DLL's rather than the original's, so the hydration callback supplies the attacker's bytes while Defender's clean engine performs the write. Because MsMpEng.exe is the process that writes the file, the write itself looks expected, which LevelBlue flags as a triage detail that must be correlated rather than dismissed. The proof-of-concept then maps the resulting DLL as an executable image to stop remediation removing it, crafts a Windows Error Report into the report queue, and triggers the built-in QueueReporting scheduled task through the Task Scheduler COM interface method ITaskService::Run(); that task runs as SYSTEM, so the signed Windows error-reporting binary wermgr.exe processes the report and loads phoneinfo.dll with SYSTEM privileges, a trusted system binary acting as the proxy that executes the attacker's code, which is how the payload runs without the attacker ever launching a process of their own. LevelBlue states the whole sequence takes approximately eight to twelve seconds on an unloaded system, and that it "is fully self-contained and runs to full SYSTEM completion from a standard user account on any fully patched Windows 11 24H2 or Windows Server 2025 system with Windows Defender in its default configuration."

Detection, in the report's own framing, "is best detected through behavioral correlation rather than any single static indicator", but one static indicator is close to free. LevelBlue identifies C:\Windows\System32\phoneinfo.dll as the strongest single indicator in the chain and states the file is not expected to exist natively on supported Windows versions, so its creation warrants a high-priority look regardless of the process that wrote it. (The hedge is the source's own and is worth keeping: "not expected on supported versions" is what it will bear, not a guarantee about every Windows build ever shipped.) Beyond that, and led by telemetry class: in image- and module-load telemetry, MpClient.dll loaded by a process that is not one of Defender's own small set of expected consumers (the report names MsMpEng.exe, MpCmdRun.exe, NisSrv.exe, ConfigSecurityPolicy.exe and MpSigStub.exe) is the compound signal, and LevelBlue is specific about what makes it load-bearing: "The set of expected MpClient.dll consumers is small. A load by an unrelated process becomes especially significant when followed by runtime resolution of MpManagerOpen, MpScanStart, MpCleanOpen, MpCleanStart, or MpCleanControl." The same telemetry should surface wermgr.exe loading phoneinfo.dll. In scheduled-task audit records, the QueueReporting task being started programmatically through the Task Scheduler COM interface is the execution step. In registry or filter telemetry, a sync-root registration call issued by a process that is not a cloud-sync client is the setup step. And in named-pipe telemetry this specific proof-of-concept creates a pipe with a hardcoded name, with a SYSTEM-integrity process then connecting to a pipe a normal user created, though that name is an artefact of this build rather than of the technique.

Triage: every individual event here has a benign twin, which is why the sequence is the detection. MsMpEng.exe writing into System32 is normal remediation behaviour; a cloud-sync provider registering a sync root is normal on a machine running OneDrive or a similar client; wermgr.exe running as SYSTEM off a scheduled task is normal error reporting. The discriminators are the process identities and the ordering: a sync-root registration from something that is not a sync client, MpClient.dll resolved by a non-Defender process followed by that specific clean-function set, and a QueueReporting run driven through COM rather than by the ordinary error-reporting trigger, with the whole chain completing inside roughly ten seconds. Hardening was the awkward part while the flaw was unpatched: because the abused component is Defender itself in its default configuration, there was no configuration change to apply, and the vulnerable-driver blocklist and application-control policies have nothing third-party to key on. Microsoft has since shipped an engine fix, so updating the Defender engine is now the primary control, see the 2026-09-13 update below.

Updaterun 2026-09-13T1307Z-auditheadlinesummarytagscvesactionssourcesevidencebody

Microsoft has shipped a fix, and this entry's standing "no fix available" status was stale. Microsoft's own record for CVE-2026-69414 now carries a remediation boundary in its structured fields: "Last version of the Microsoft Malware Protection Engine affected by this vulnerability" reads 1.26070.7, and "First version of the Microsoft Malware Protection Engine with this vulnerability addressed" reads 1.1.26080.3 (Microsoft MSRC, latest revision 2026-09-03). The record's CVSS vector carries RL:O (an official fix) against the E:P proof-of-concept maturity it already had. The practical point for a defender is that the Defender engine version updates on its own cadence and is not the same thing as the OS patch level, so an estate that is fully current on Windows Update is not thereby on engine 1.1.26080.3; check the engine version explicitly. That replaces detection-as-the-only-control, which is what this entry has told readers since 2026-08-12.

The same researcher now claims the fix is incomplete, as their own claim, not a confirmed one. On 2026-09-08 Nightmare Eclipse published ShieldCrash, described in the researcher's own repository as a partial rather than total bypass: "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited" (Nightmare Eclipse, 2026-09-08). What is published is explicitly unfinished and narrower than the original: SOCRadar records that "ShieldCrash does not currently have a separate CVE. Nightmare Eclipse describes the public release as a skeleton PoC that demonstrates privileged file reads. It does not establish arbitrary file writes or SYSTEM-level code execution" (SOCRadar, 2026-09-10), and that "Microsoft has not publicly confirmed the reported bypass" (SOCRadar, 2026-09-10). Microsoft's record predates the ShieldCrash release by five days and acknowledges no bypass. SOCRadar also states there is no confirmed in-the-wild exploitation of ShieldCrash.

vulnerability12 Aug 04:47Zmulti-sourceOpen finding →

2026-09-06 · view entry permalink →

HIGHupdatedNATOB1

Chaotic Eclipse turns its zero-day drops on third-party security products: local privilege escalation in CrowdStrike Falcon and Avast, with working proof-of-concept code public; all three vendors have since remediated

The pseudonymous researcher tracked here as Nightmare Eclipse, and by The Hacker News under the further aliases Chaotic Eclipse, INFINITE NIGHTMARE and MSNightmare, spent 2026 publishing working proof-of-concept exploits for Windows and Microsoft Defender privilege escalations without giving the vendor advance notice. In early September the target set changed: three of the four latest drops are against third-party endpoint security products rather than Microsoft's, and at disclosure two of them had no fix (The Hacker News, 2026-09-03); both are now reported remediated (see the update below). That shift is what makes this an operational matter for estates that never had Defender in scope.

FalconFlank abuses CrowdStrike Falcon Sensor's Office malicious-macro remediation path. The remediation routine runs at high privilege in order to clean an infected document in place, and the exploit turns that cleanup into a low-privileged account's route to SYSTEM. Truesec, reading the release independently, records the preconditions precisely: the proof-of-concept "works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon – Phase 3 Optimal Protection with 'Microsoft Office file malicious macro removal' setting" (Truesec, 2026-09-04). A CrowdStrike spokesperson told The Hacker News the company is "actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting", adding that customers "remain protected through the Cloud Anti-malware for Microsoft Office Files settings" (The Hacker News, 2026-09-03). At disclosure there was no patch and no CVE, and the only control on offer was turning a prevention feature off, which Truesec notes means malicious macros will no longer be replaced in place while cloud-side blocking continues (Truesec, 2026-09-04); CrowdStrike is now reported to have remediated the flaw (see the update below).

PrettyPrague is the same shape against a different vendor. The researcher describes it as dumping the SAM database "by abusing a vulnerability in Avast Sandbox" and spawning a full SYSTEM shell against fully patched Avast Antivirus on a patched Windows 11 25H2 host, and states a belief that other Gen Digital products including AVG and Norton are affected (The Hacker News, 2026-09-03). Gen Digital confirmed a vulnerability "affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges" and said at the time it was "actively developing a patch", without naming which further products are in scope (The Hacker News, 2026-09-03); Gen Digital is now reported to have shipped that fix (see the update below). The third drop, HardBreacher against Kaspersky Endpoint Security for Windows 14.0.0.504, is the one that is resolved: Kaspersky told the same outlet the fix ships through an automatic database update or a manually triggered one (The Hacker News, 2026-09-03). A fourth release, GreenSection, is described only as an NVIDIA memory-corruption bug that crashes any application using Vulkan or OpenGL, rather than a privilege escalation (The Hacker News, 2026-09-03).

The releases are unco-ordinated by the researcher's own account, and the reason they give matters for timeline planning rather than attribution. The Hacker News reports the researcher claiming that Microsoft continues to ignore them and refuses to engage in "any sort of communication", and quotes them saying they "can't even report the bugs I find to their respective vendors because of the restrictions by Microsoft" (The Hacker News, 2026-09-03). The same reporting quotes them planning the timing of future drops: "Think I will start publishing bugs for third-parties in that window where Patch Tuesday isn't released yet" (The Hacker News, 2026-09-03). For a defender that means there is no embargo to wait out and no co-ordinated patch date, the gap between publication and a vendor fix is open-ended, and by the researcher's own stated intent the next drop is likelier to land in the days before a Patch Tuesday than after one.

Triage: these exploits ride a security agent's legitimate high-privilege routines, so the signal is not the agent acting with privilege, which it always does. What separates abuse is what the privileged action produces: a remediation or sandbox operation followed by a process spawning from an unexpected parent under a low-privileged user's session, a write into a system directory that the agent's normal cleanup does not target, or SAM access originating from the antivirus process tree rather than from a backup or credential-management workflow. Because the code is public and the researcher notes detections may already exist, an endpoint alert naming the agent's own remediation component is worth treating as an exploitation attempt rather than a product fault.

We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting

The Hacker News (quoting a CrowdStrike spokesperson)

As of now the PoC works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon – Phase 3 Optimal Protection with “Microsoft Office file malicious macro removal” setting.

Truesec 2026-09-04

Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges. We immediately initiated our security response procedures and are actively developing a patch.

The Hacker News (quoting a Gen Digital spokesperson)

Every Windows logon session has a private object directory inside the kernel's namespace – \\Sessions\\0\\DosDevices\\{AuthId}\\, and any standard user process can place symbolic links inside their own session's directory without any special privilege.

The vulnerability is that a standard user process can send IOCTL 0x82AC0054 directly to the aswSnx driver to request that a chosen executable be run inside the sandbox.

For CrowdStrike clients to be susceptible to this local privilege escalation vulnerability, an endpoint must be assigned to a Prevention Policy with the "Microsoft Office file malicious macro removal" setting enabled. This vulnerability does not impact CrowdStrike Falcon Government clients.

LevelBlue (Trustwave) SpiderLabs 2026-09-09

As of September 4, 2026, Gen has released a patch for the following versions of Avast Antivirus for Windows

The Hacker News 2026-09-03
Updaterun 2026-09-10T0410Z-inteltitleheadlinesummarytagsactionsentitiestechniquessourcesevidencesourcing_noteclassificationbody

LevelBlue SpiderLabs independently reproduced and analysed all four PoCs, adding mechanism-level detail none of the original vendor statements carried. HardBreacher: "every Windows logon session has a private object directory inside the kernel's namespace – \Sessions\0\DosDevices\{AuthId}\, and any standard user process can place symbolic links inside their own session's directory without any special privilege" (LevelBlue SpiderLabs, 2026-09-09); the exploit builds a fake filesystem tree redirecting Kaspersky's avpuimain.dll load path to an attacker DLL, then spawns avpui.exe suspended with the redirect live and resumes it so the OS loader loads the malicious DLL, additionally using NtCreateUserProcess with the parent-process attribute set to explorer.exe so EDR process-tree telemetry records Explorer, not the real caller, as the parent, the payload then hides and terminates the product's user-facing notification process from inside. PrettyPrague: "the vulnerability is that a standard user process can send IOCTL 0x82AC0054 directly to the aswSnx driver to request that a chosen executable be run inside the sandbox" (LevelBlue SpiderLabs, 2026-09-09), where the sandbox's virtualized SAM-hive copy carries none of the real SAM's ACLs; the exploit races the sandbox's own cleanup to copy the hive out via a rolled-back Kernel Transaction Manager transaction, decrypts NTLM hashes offline using the LSA boot key, and reaches a SYSTEM context through a CMSTPLUA COM-interface UAC bypass to log in as every local admin, reverting the passwords afterward. FalconFlank's precondition is narrower than the original report suggested: "for CrowdStrike clients to be susceptible to this local privilege escalation vulnerability, an endpoint must be assigned to a Prevention Policy with the 'Microsoft Office file malicious macro removal' setting enabled. This vulnerability does not impact CrowdStrike Falcon Government clients" (LevelBlue SpiderLabs, 2026-09-09), and in LevelBlue's own lab testing, CrowdStrike's cloud-based ML engine (detection logic OnWriteOfficeMacroMLMedium) identified and quarantined the malicious DLL the exploit stages, preventing the final privilege-escalation step in that test run, a detection outcome that limits, without eliminating, the real-world exploitability the initial disclosure implied. LevelBlue independently characterises GreenSection differently from the original report's "memory-corruption bug that crashes any application using Vulkan or OpenGL": its own analysis describes a standard user opening, mapping, modifying and restoring an NVIDIA global shared-memory section, with no privilege-escalation or code-execution primitive demonstrated, a narrower, trust-boundary-design finding rather than a crash bug, though LevelBlue did not claim to have tested for a crash condition either.

LevelBlue's closing assessment also updates the patch picture this entry originally carried: "PrettyPrague demonstrated the most significant security impact prior to remediation, while HardBreacher highlighted opportunities for security-product abuse and evasion. GreenSection is primarily a security design concern, and FalconFlank's operational relevance was limited both by its configuration-dependent exposure and by rapid vendor remediation" (LevelBlue SpiderLabs, 2026-09-09); both FalconFlank and PrettyPrague are now reported remediated, which supersedes the "no fix"/"still developing a patch" status this entry carried at disclosure. The Hacker News's own update to its original report names a specific fix: "as of September 4, 2026, Gen has released a patch for the following versions of Avast Antivirus for Windows - 26.7.11086, fix version 992 [and] 26.8.11125, fix version 993" (The Hacker News, 2026-09-03). No source reached for this entry names a specific fixed CrowdStrike Falcon build or date for FalconFlank; confirm current release status directly with CrowdStrike rather than treating this as a version-checkable patch.

vulnerability06 Sep 14:00Zmulti-sourceOpen finding →

Earlier coverage (5)

2026-07-29NOTABLEupdatedNATOB2LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systemsLevelBlue SpiderLabs published a full analysis on 2026-07-27 of LegacyHive, the latest public Windows proof-of-concept from the Nightmare Eclipse disclosure persona. It is not a software vulnerability: the chain edits a helper account's ntuser.dat offline through Microsoft's own Registry Offline API, repoints the User Shell Folders Local AppData value into an attacker-created NT Object Manager namespace, uses a batch opportunistic lock on UsrClass.dat to pause until profile initialisation reaches the right moment, then forces a profile load via CreateProcessWithLogonW with LOGON_WITH_PROFILE, aliasing into a third account's profile data without ever holding that account's credentials. LevelBlue reproduced the whole chain on fully patched Windows with July 2026 updates installed and reports no Microsoft mitigation for this class of abuse. It is strictly post-compromise: the attacker needs a low-privileged session plus a separate helper account's credentials.2026-07-09NOTABLECVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day seriesNCSC-CH's Nightmare Eclipse tracker was updated on 2026-07-09 to record that a CVE has been assigned to RoguePlanet (CVE-2026-50656), a link-following (CWE-59) local privilege escalation in the Microsoft Malware Protection Engine behind Defender that lets a local attacker reach SYSTEM; Microsoft's MSRC record shows the engine fix has now shipped. A public PoC existed from 2026-06-10 and the CVE sat in "no fix" for over three weeks. The engine auto-updates, so most estates are already current, but WSUS-gated, offline or OT-adjacent estates should explicitly verify the installed engine build.2026-06-19HIGHNightmare/Chaotic Eclipse zero-day wave; the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patchESET detailed GentleKiller, an operator-maintained EDR-killer framework run centrally by the Gentlemen RaaS gang, eight BYOVD driver variants against 400+ security processes across 48 product families, with confirmed Western-European targeting (ESET, 2026-06-18). Microsoft's Defender LPE zero-day from the Nightmare Eclipse wave now carries a CVE (CVE-2026-50656) with a public PoC and no patch.2026-05-30NOTABLENightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 dropUPDATE (originally covered 2026-W21): Microsoft's Digital Crimes Unit issued a formal public statement on 28–29 May 2026 calling uncoordinated zero-day releases "never justifiable" and warning its DCU would "continue bringing cases against these actors and those that enable their criminal activity" (The Record …2026-05-19NOTABLEChaotic Eclipse Windows zero-days; MiniPlasma is third PoC in series; cldflt.sys CfAbortHydration path, claimed re-exploitable CVE-2020-17103 regressionUPDATE (originally covered 2026-05-15): Researcher "Chaotic Eclipse" / "Nightmare Eclipse" released a third unpatched Windows LPE PoC on 2026-05-17 (MiniPlasma) extending the YellowKey and GreenPlasma series covered in the 2026-05-15 daily (BleepingComputer, 2026-05-17; The Hacker News, 2026-05-18).

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns6
  • Threats3
  • Research2

Source distribution

  • msrc.microsoft.com5 (15%)
  • levelblue.com4 (12%)
  • bleepingcomputer.com3 (9%)
  • thehackernews.com3 (9%)
  • security-hub.ncsc.admin.ch2 (6%)
  • securityweek.com2 (6%)
  • theregister.com2 (6%)
  • 0patch.com1 (3%)
  • other11 (33%)
All cited sources (33)