HardBreacher’s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or assigned a CVE by Kaspersky.
The project, published by a researcher, MSNightmare, describes the alleged flaw as a zero-day elevation-of-privilege vulnerability in Kaspersky’s enterprise endpoint product.
According to the repository’s README, the proof of concept was tested on Windows 11 version 25H2 with Kaspersky Endpoint Security version 14.0.0.504. HardBreacher appears to target the interaction between a local user and a Kaspersky user-interface process.
MSNightmare claims that successful exploitation can create a DLL file at C:WindowsSystem32MY_SNAKE_IS_SOLID.dll and grant the current user full permissions on the file.
Because System32 is normally protected, the result, if reproducible, could indicate that a low-privileged local user can gain access beyond their intended Windows security boundary.
HardBreacher Kaspersky Zero-Day
The repository does not describe a reliable exploit chain in detail. Its author says the proof of concept is unstable, may terminate with errors, and often requires multiple attempts to succeed.
MSNightmare also states that a reboot was involved during testing. Those limitations are important: a public proof of concept can support investigation, but it does not independently establish broad exploitability across all deployments, configurations, or product builds.
Still, the alleged impact is notable. The README claims that gaining control of the targeted Kaspersky UI process can disrupt the security product’s normal operation.
The reporter MSNightmare says this could lead to unexpected allow-or-block decisions involving files and potentially leave the endpoint in an unstable state.
A dependable version of such an exploit could be particularly concerning in enterprise environments, where endpoint security software runs with powerful privileges and has deep access to files, processes, and policy enforcement controls.
Privilege-escalation flaws in security products are high-value targets because they can turn defensive tooling into an attack path.

An attacker who already has code execution as a standard Windows user may seek elevated privileges to turn off protections, alter security configurations, access protected data, establish persistence, or move laterally.
The actual severity of HardBreacher, however, depends on whether the reported behavior can be reproduced and whether exploitation requires additional local permissions, specific product settings, or user interaction.
Organizations using Kaspersky Endpoint Security should treat the public claim as a potential security signal rather than a confirmed vulnerability.
Security teams should monitor Kaspersky’s advisories and support channels for validation, patches, mitigations, or an official security bulletin.
They should also review telemetry for unusual activity involving Kaspersky processes, unexpected changes in System32, anomalous DLL creation, and security-service failures.
Until vendor confirmation is available, defenders should avoid testing the public code on production endpoints. The repository’s author warns that the proof of concept can destabilize the operating system, creating both operational and security risks during investigation.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post HardBreacher PoC Claims Kaspersky Endpoint Security Zero-Day Privilege Escalation on Windows 11 appeared first on Cyber Security News.
