Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
HardBreacher — Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability | Kitploit
Tools/GitHubGitHub/msnightmare/hardbreacher
Privilege EscalationExploit FrameworksVulnerability AnalysisExploitation
GitHubmsnightmare/hardbreacher

HardBreacher

Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability

View Repository
11431101 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

HardBreacher

Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability

So the problem is now leaking outside of Microsoft, there was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version.

At the time of writing this, the proof of concept works in a fully patched windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504

The PoC is not in the best shape at all, it is basically duct tapped, I just managed to make it work and that's all. It will fail to run with error so you just have to keep rerunning it. If it succeeds, it will create a file in C:\Windows\System32\MY_SNAKE_IS_SOLID.dll will full permissions for current user.

The interesting part about this is the Kaspersky completely loses it when you take control over the UI process, you can cause it to stop functioning, grant/block access to files its not supposed to, if the PoC succeeds, the entire operating system becomes a hot mess.

Anyways, here is a useless screenshot about where I tested it and it worked (after a reboot) Untitled

Regardless, I still think this can be turned into a stable silent one click exploit, I just don't have the time and resources to do it.

Download Tool