Skip to content
Tech News
← Back to articles

Avast's Kernel Driver Vulnerability Enables Sandbox Escape on Windows 11

read original more articles
GoKawiil Brief

Researchers identified a double-fetch flaw in Avast's kernel driver that can lead to a pool overflow, potentially allowing code execution outside the antivirus sandbox. The flaw involves multiple reads of the same user-supplied data, which can be manipulated between fetches. Recent Windows updates mitigate this issue by enforcing user-mode access checks, reducing the exploit's viability.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

This vulnerability highlights the risks associated with kernel-level security flaws in widely used antivirus software, which could be exploited to escalate privileges or bypass security measures. The mitigation introduced in newer Windows versions underscores the importance of operating system defenses in preventing such exploits, but also suggests that older systems remain vulnerable if not patched.

Key Takeaways

Source: safateam.com — Safa Team, 2026-09-25

Published there as: “CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.