Hacker News·6 min read·hard

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

S
safateam
CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
✦AI Summary

This technical blog post details the exploitation of CVE-2025-13032, a double-fetch vulnerability found in Avast Antivirus kernel drivers. The authors explain how they bypassed security measures on Windows 11 to achieve privilege escalation.

Why it matters

Understanding these vulnerabilities is critical for cybersecurity professionals to patch systems and prevent malicious actors from gaining kernel-level access.

✦Dive DeeperCreate a free account to unlock

All posts CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 This post is the second and final part of our Avast Antivirus research, detailing the full exploitation of CVE-2025-13032 on an up-to-date Windows 11 system. Starting from the double-fetch vulnerability introduced in Part 1, we walk through how the controlled paged pool overflow was turned into an arbitrary kernel read/write primitive by corrupting the RegBuffers array of the IORing object. The post covers the heap spray strategy, the kernel address leak via MDL introspection, the repairs needed to avoid a blue screen on teardown, and the final privilege escalation to SYSTEM via token theft.

This blogpost is the second and final part of our Avast research and will focus on the exploitation of CVE-2025-13032, a double-fetch vulnerability we discovered in Avast’s kernel driver.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in