PT-2025-46368 · Avg+1 · Avg Antivirus+1

·

CVE-2025-13032

·

Published

2025-11-11

·

Updated

2025-12-07

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avast/AVG Antivirus versions prior to 25.3
Description A double fetch race condition exists in the Avast/AVG kernel sandbox driver on Windows. This condition allows a local attacker to escalate privileges through a pool overflow. The issue involves a break-in and escape from the antivirus sandbox, potentially leading to a SYSTEM token heist.
Recommendations Update Avast/AVG Antivirus to version 25.3 or later.

Fix

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13032

Affected Products

Avg Antivirus
Avast Antivirus