PT-2026-93757 · Ge Digital · Avg Antivirus Free+2
CVE-2026-82964
·
Published
2026-09-16
·
Updated
2026-09-30
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avast sandbox driver (aswSnx.sys) (affected versions not specified)
Description
Improper preservation of permissions in the
aswSnx.sys minifilter driver on Windows allows a local, low-privileged attacker operating within the sandbox to escape file isolation and escalate privileges to SYSTEM. The issue occurs because the driver fails to apply the original security descriptor to virtualized files due to the omission of the WRITE DAC (Write Discretionary Access Control List) permission when opening the virtualization target object. Additionally, the IRP MJ CREATE callback does not strip WRITE DAC for sensitive directories, enabling a sandboxed process to rewrite the security descriptor of a virtualized object. This allows an attacker to read virtualized copies of the SAM (Security Accounts Manager) database, extract local NTLM password hashes, and execute code as SYSTEM. The driver also lacks an IRP MJ SET SECURITY callback in its operation registration table.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Preservation of Permissions
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avg Antivirus Free
Avast Free Antivirus
Norton Antivirus Plus