B
今週中
セキュリティ研究者のChaotic Eclipseが、Kaspersky Endpoint Securityの権限昇格の脆弱性を悪用するPoC「HardBrea…
📌 一言でいうと
セキュリティ研究者のChaotic Eclipseが、Kaspersky Endpoint Securityの権限昇格の脆弱性を悪用するPoC「HardBreacher」を公開しました。このエクスプロイトは、完全にパッチが適用されたWindows 11 25H2上のKaspersky Endpoint v14.0.0.504で動作し、System32にDLLを作成することが可能です。また、KasperskyのUIプロセスを制御することで、アンチウイルス機能を妨害し、システムを不安定な状態にする可能性があるとされています。
🔍該当判定
- Kaspersky Endpoint Security を導入している
- Windows 11 (バージョン 25H2) を利用している
- Kaspersky Endpoint のバージョンが v14.0.0.504 である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーからの修正パッチの提供を確認し、速やかに適用すること。また、不審なDLLの作成やシステムプロセスの異常な挙動がないか監視を強化すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Kaspersky Endpoint Security 権限昇格の脆弱性 (HardBreacher) について
お疲れさまです。Kaspersky Endpoint Securityに関する脆弱性情報共有です。
■ 概要
セキュリティ研究者により、権限昇格を可能にするPoC「HardBreacher」が公開されました。成功した場合、System32ディレクトリへのDLL作成や、アンチウイルス機能の妨害が行われる可能性があります。
■ 影響範囲
- 対象製品: Kaspersky Endpoint Security v14.0.0.504
- 対象OS: Windows 11 25H2
■ 対応手順
1. 自社環境で利用しているKaspersky Endpoint Securityのバージョンを確認してください。
2. ベンダーから本件に関する修正パッチがリリースされているか確認し、適用を検討してください。
3. System32内への不審なDLL作成などの不審な挙動がないか、EDR等で監視を強化してください。
■ 参考情報
- secaffairs 記事: Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher
対応優先度: 高
対応期限: 速やかに確認
お疲れさまです。Kaspersky Endpoint Securityに関する脆弱性情報共有です。
■ 概要
セキュリティ研究者により、権限昇格を可能にするPoC「HardBreacher」が公開されました。成功した場合、System32ディレクトリへのDLL作成や、アンチウイルス機能の妨害が行われる可能性があります。
■ 影響範囲
- 対象製品: Kaspersky Endpoint Security v14.0.0.504
- 対象OS: Windows 11 25H2
■ 対応手順
1. 自社環境で利用しているKaspersky Endpoint Securityのバージョンを確認してください。
2. ベンダーから本件に関する修正パッチがリリースされているか確認し、適用を検討してください。
3. System32内への不審なDLL作成などの不審な挙動がないか、EDR等で監視を強化してください。
■ 参考情報
- secaffairs 記事: Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher
対応優先度: 高
対応期限: 速やかに確認
Subject: [Technical Alert] Privilege Escalation Vulnerability in Kaspersky Endpoint Security (HardBreacher)
Dear IT/Security Team,
We are sharing information regarding a newly released PoC exploit named "HardBreacher" targeting Kaspersky Endpoint Security.
■ Overview
An exploit has been released that triggers a privilege escalation flaw. If successful, it allows an attacker to create a DLL in the System32 directory and potentially disrupt antivirus functions by taking control of the UI process.
■ Affected Scope
- Product: Kaspersky Endpoint Security v14.0.0.504
- OS: Windows 11 25H2
■ Recommended Actions
1. Verify the version of Kaspersky Endpoint Security deployed in your environment.
2. Monitor for official patches from the vendor and apply them immediately upon release.
3. Enhance monitoring for unauthorized DLL creation in System32 or abnormal behavior of Kaspersky processes.
■ Reference
- Source: secaffairs (Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher)
Priority: High
Deadline: Immediate review
Dear IT/Security Team,
We are sharing information regarding a newly released PoC exploit named "HardBreacher" targeting Kaspersky Endpoint Security.
■ Overview
An exploit has been released that triggers a privilege escalation flaw. If successful, it allows an attacker to create a DLL in the System32 directory and potentially disrupt antivirus functions by taking control of the UI process.
■ Affected Scope
- Product: Kaspersky Endpoint Security v14.0.0.504
- OS: Windows 11 25H2
■ Recommended Actions
1. Verify the version of Kaspersky Endpoint Security deployed in your environment.
2. Monitor for official patches from the vendor and apply them immediately upon release.
3. Enhance monitoring for unauthorized DLL creation in System32 or abnormal behavior of Kaspersky processes.
■ Reference
- Source: secaffairs (Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher)
Priority: High
Deadline: Immediate review