Menu

Post image 1
Post image 2
Post image 3
Post image 4
Post image 5
Post image 6
Post image 7
Post image 8
Post image 9
Post image 10
Post image 11
1 / 11
0

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

Hacker News·about 10 hours ago
#voRjBgrT
#safateam#avast#kernel#sandbox#photo#article
Reading 0:00
15s threshold

Introduction This blogpost is the second and final part of our Avast research and will focus on the exploitation of CVE-2025-13032, a double-fetch vulnerability we discovered in Avast’s kernel driver. This post recaps the bug and walks through how we exploited it on an up-to-date Windows 11 system at the time of the finding. Feel free to read the first part if you missed it → https://www.safateam.com/intelligence-hub/research/technical-articles/cve-2025-13032-entering-and-breaking-the-avast-antivirus-sandbox-part-1 Note: In the latest version the windows kernel and drivers are using user-mode accessors ( https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/user-mode-accessors ) to verify each kernel access to user-mode memory and ensure at each access that user-buffers are in fact reside in userspace.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More