Wednesday September 16, 2026

Advisory ID:   ngCERT-2026-090002

Damage:      Critical 

Probability:  High

Platform(s):  Kaspersky Endpoint Security version 14.0.0.504; Windows 11 Version 25H2

SUMMARY

ngCERT has observed the public release of HardBreacher, a proof-of-concept (PoC) that claims to exploit a Local Privilege Escalation (LPE) vulnerability in Kaspersky Endpoint Security for Windows. The PoC was tested on a fully patched Windows 11 Version 25H2 system running Kaspersky Endpoint Security Version 14.0.0.504 and may allow a low-privileged user to write a DLL to the protected C:\Windows\System32 directory. The vulnerability has not been assigned a CVE, and the publicly available PoC is unstable and has not been independently verified to provide reliable SYSTEM-level code execution. Kaspersky has addressed the underlying issue. Organisations using Kaspersky Endpoint Security are advised to verify the affected versions in their environments and ensure that the applicable vendor remediation has been applied.

DESCRIPTION

HardBreacher is a PoC that targets a LPE vulnerability in Kaspersky Endpoint Security for Windows. The PoC demonstrates the interaction between a standard Windows user and a privileged process, which may allow unauthorised file operations within the protected C:\Windows\System32 directory, including the creation of MY_SNAKE_IS_SOLID.dll with permissions accessible to the initiating user. The PoC was demonstrated on Windows 11 Version 25H2 with Kaspersky Endpoint Security Version 14.0.0.504 and requires local access or prior code execution on the endpoint. The exploit is unreliable and may require multiple attempts or a system reboot, while current analysis does not independently confirm dependable SYSTEM-level code execution, all affected product versions, or a CVE assignment. Public availability of the PoC could enable attackers to improve its reliability or combine the technique with other methods to achieve further privilege escalation, modify protected resources, disrupt endpoint security controls, or establish persistence. Organisations are advised to verify applicable vendor remediation and monitor for unauthorized DLL creation or modification, abnormal Kaspersky process activity, security-service disruptions, and suspicious privilege changes.

CONSEQUENCES

Successful exploitation could result in:

    1. Escalation of privileges from a standard user to SYSTEM-level access.
    2. Unauthorised modification of protected Windows system resources.
    3. Execution of malicious code with elevated privileges.
    4. Disruption or bypass of Kaspersky Endpoint Security controls.
    5. Establishment of persistence on affected endpoints.
    6. Exposure of sensitive data, credentials, and system resources.
    7. Potential lateral movement and further compromise of other organisational systems. 

SOLUTION/MITIGATION

ngCERT recommends the following:

    1. Verify all endpoints running Kaspersky Endpoint Security and apply the applicable Kaspersky vendor remediation or security update, particularly Version 14.0.0.504.
    2. Keep Windows and Kaspersky Endpoint Security fully updated.
    3. Enforce least-privilege access and restrict unnecessary administrative privileges.
    4. Monitor C:\Windows\System32 for suspicious DLL creation or modification.
    5. Review EDR, SIEM, and Windows logs for abnormal activity and privilege changes.
    6. Do not execute the HardBreacher PoC on production systems.
    7. Isolate and investigate affected endpoints where exploitation is suspected.  

HYPERLINK