A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component.
The code was published by a GitHub user named MSNightmare and is being presented as a zero-day vulnerability. However, the vendor has not confirmed it.
HardBreacher Exploit Kaspersky Endpoint Security
According to the project’s README, the author tested this proof of concept on a patched Windows 11 system running Kaspersky for Endpoint version 14.0.0.504.
The repository describes the issue as a privilege-escalation weakness, stating that when exploited, it creates a file named C:WindowsSystem32MY_SNAKE_IS_SOLID.dll with full permissions granted to the user.
Reports MSNightmare describe this as a local path from a standard user to SYSTEM-level privileges; however, independent validation and a response from Kaspersky were not available at the time of publication.
It is important to note that HardBreacher is not a remote initial-access exploit. An attacker would first need to execute code or have access to a local account.
Despite this prerequisite, the risk remains, as local privilege escalation can be used in conjunction with phishing, malware execution, or an initial compromise.
This could lead to disabling defenses, accessing protected data, establishing persistence, or moving laterally using credentials and tokens exposed to a higher-privileged context.
The author characterizes the current code as unreliable, noting that it may fail with errors and require multiple attempts to execute. This limitation should not be mistaken for mitigation.
The publication of this proof-of-concept code lowers the barrier for both researchers and adversaries to analyze the affected attack surface, refine its reliability, or incorporate this technique into a multi-stage intrusion.
The README also claims that gaining control of the product’s user interface can destabilize Kaspersky’s functionality, potentially leading to unexpected file access decisions and disrupting the software’s security features.
At the time of reporting, organizations should treat these claims as unverified but still significant. Security teams should inventory endpoints running Kaspersky Endpoint Security for Windows or the specified Kaspersky for Endpoint version, preserve version and policy data, and await vendor advisories, CVE assignments, detection guidance, or fixes.
Administrators should avoid executing the public proof of concept on production systems.
To reduce exposure, defenders can enforce the principle of least privilege, limit interactive access for regular users, and investigate any anomalous writes or permission changes under C:WindowsSystem32.
Telemetry should also be reviewed for unexpected child processes originating from Kaspersky user interface components, security service interruptions, abrupt configuration changes, and DLL creation in protected directories. Endpoint detection teams should establish a baseline of legitimate Kaspersky processes before creating alerts to minimize false positives.
Organizations should test vendor-supplied remediation in a controlled environment and then prioritize deployment across shared workstations, developer endpoints, and administrator systems.
Until Kaspersky confirms the scope of the issue and releases a fix, the recommended approach is heightened monitoring, strict local access controls, and rapid incident triage for any evidence that an unprivileged account has altered protected operating system paths.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

