DEV Community

Cover image for Zero-Day Exploits Target CrowdStrike, Kaspersky, and Avast EDR Platforms
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Zero-Day Exploits Target CrowdStrike, Kaspersky, and Avast EDR Platforms

Summary

Researcher Chaotic Eclipse released two more zero-day exploits (FalconFlank and PrettyPrague) that allow local privilege escalation by abusing the remediation and sandbox features of CrowdStrike and Avast security software.

Take Action:

If you use CrowdStrike Falcon or Avast/Norton/AVG on Windows 11 or Windows Server 2025, watch closely for vendor patches and apply them the moment they are released. Don't assume your antivirus catching the public exploit code means the underlying flaw is fixed.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)