Nightmare-Eclipse Releases Yet Another Devastating Windows 0-day Vulnerability
The prolific and controversial security researcher who goes by Nightmare-Eclipse released a ninth 0-day vulnerability that allows an attacker to gain SYSTEM level privileges.
The vulnerability, titled ShieldBreak, exploits Microsoft Defender and leverages its SYSTEM level access. This new exploit is actually a continuation of an older one released by Nightmare-Eclipse called RoguePlanet.
According to the researcher, Microsoft didn’t properly patch RoguePlanet and the patch can be completely bypassed.
The original RoguePlanet was based on a race condition, meaning that it relies on specific timing in order to work. Usually this means an exploit won’t work 100% reliably, and they described RoguePlanet as “hit or miss” in their original proof-of-concept on GitHub. They also said it might be possible to redesign it so it could have a 100% success rate.
The new proof-of-concept for ShieldBreak claims a 100% success rate although they say Windows 10 systems aren’t fully supported even though the exploit still affects them.
Normally, security researchers go through a coordinated vulnerability disclosure process with vendors like Microsoft to ensure enough time for them to patch the vulnerability before publishing the details.
0-days, however, are not known by the vendor and thus they can be exploited while the software developers make a patch. Nightmare-Eclipse has made a point of intentionally releasing their vulnerabilities to the public without giving Microsoft time to patch them.
All this is to get back at Microsoft for some personal slight. They’re unique among threat actors as their actions aren’t driven by money or political activism but a personal grudge against the Microsoft.
Their exploits have seen use in real-world attacks against Windows and caused real damage.
As Microsoft hits record numbers of vulnerabilities patched in updates this year, the current record sitting at 622 flaws fixed in their July patch Tuesday, this is yet more workload that they’ll have to contend with.
The fact that the bug can bypass their original patch suggests a flawed approach Microsoft is taking to fixing bugs, potentially leaving more half-fixes just waiting to be reopened.
The unprecedented onslaught of AI-assisted vulnerability research has tested the capacity of companies to keep up with the constant stream. It’s unclear if the plan is to keep playing whack-a-mole with vulnerabilities or if there’s a longer term plan to harden operating systems against exploits such as these. It’s difficult to imagine the current state of cybersecurity being sustainable for the long term.
Community Discussion