Avast sandbox driver double-fetch allowed local privilege escalation via pool overflow

Avast sandbox driver double-fetch allowed local privilege escalation via pool overflow

CVE-2025-13032 affects Avast and AVG Antivirus before 25.3 on Windows. The sandbox kernel driver double-fetches a user-supplied _UNICODE_STRING Length, allocating with ExAllocatePoolWithTag then copying with memmove. A concurrent change triggers a kernel pool overflow, giving a local attacker privilege escalation.

Published

Read at another depth