TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Safa Team’s second and final post on CVE-2025-13032 describes how researchers exploited a double-fetch flaw in an Avast kernel driver to cause a pool overflow and pursue local privilege escalation. The post says a newer Windows kernel mitigation prevents the specific technique; the source does not establish the vulnerability’s current patch status or whether it was exploited outside research.
Safa Team has published the second and final part of its research into CVE-2025-13032, describing how researchers exploited a double-fetch flaw in an Avast kernel driver on an up-to-date Windows 11 system at the time of their finding. The researchers say the flaw could trigger a kernel pool overflow and support a local privilege escalation; they also note that a newer Windows mitigation prevents the specific technique described.
The bug involved a user-supplied UNICODE_STRING whose Length field the driver read more than once. According to the post, the driver used one read to size a kernel pool allocation and a later read to determine how much data to copy. If another thread changed the field between those operations, the copy could exceed the allocation and overflow the pool. The researchers say their proof of concept repeatedly changed the value while issuing the relevant driver request, relying on the timing of the two reads.
The post says the researchers sought to turn that overflow into an arbitrary kernel read and write capability, then use it for local privilege escalation. It identifies an I/O Ring object’s registered-buffer array as the target for corruption: the researchers said the array is allocated in paged pool, the same pool affected by the overflow, and its size can be controlled by the number of registered buffers. They describe corrupting a pointer in the array as a route to the read/write capability. These are the researchers’ technical claims; the supplied source does not independently verify the exploit or report exploitation in the wild.
Safa Team’s post also says current Windows kernel and driver code uses user-mode accessors to validate kernel access to user memory. The authors say this change blocks the exploitation method in their write-up. That statement concerns the described technique; the source does not specify which Windows releases include the mitigation, when it took effect, or whether Avast separately changed its driver.
Vulnerability Research Brief · Part 2 of 2
How To Enter And Break Out Of The Avast Antivirus Sandbox: Part 2
Safa Team’s second and final post on CVE-2025-13032 describes how researchers exploited a double-fetch flaw in an Avast kernel driver to cause a pool overflow and pursue local privilege escalation — and why a newer Windows kernel mitigation blocks the specific technique.
Exploit Chain Overview
From Bug Finding to Exploit
Part 1 covered entry into and escape from the Avast antivirus sandbox; this installment focuses on weaponizing CVE-2025-13032. The visual chain below summarizes the researchers’ described path from a user-mode request to privilege escalation.
Sandbox Escape
Part 1 of the research covered entering and escaping the Avast antivirus sandbox.
Double Fetch
A user-supplied UNICODE_STRING’s Length field is read twice by the driver.
Pool Overflow
A racing thread shrinks the Length between reads, so the copy exceeds the allocation.
Corrupt I/O Ring
Overflow targets a registered-buffer array’s pointer in the same paged pool.
Privilege Escalation
Corrupted pointer yields arbitrary kernel read/write, enabling local privilege escalation.
The Race Window
A Race in Kernel Memory Handling
The driver used one read of the Length field to size a kernel pool allocation and a later read to determine how much data to copy. The proof of concept repeatedly changed the value from another thread while issuing the driver request, relying on the timing between the two reads.
Technical Mechanics
Inside the Overflow
The overflow occurs in paged pool — kernel memory used for data that may be paged out. The Windows Segment Heap’s different allocation strategies for small and larger allocations affect how researchers arranged nearby objects.
Double-Fetched Length
A UNICODE_STRING supplied from user mode has its Length field read more than once by the Avast kernel driver. If another thread changes the field between the two operations, the copy can exceed the allocation.
I/O Ring Buffer Array
An I/O Ring object’s registered-buffer array is allocated in paged pool — the same pool affected by the overflow — and its size can be controlled by the number of registered buffers, enabling precise heap grooming.
Arbitrary R/W via Pointer
Corrupting a pointer in the registered-buffer array serves as the route to an arbitrary kernel read and write capability, which the researchers then used toward local privilege escalation.
Heap Landscape
Controlling the Paged Pool
The Windows Segment Heap uses different allocation approaches depending on size — a factor the researchers leveraged when arranging objects near the vulnerable allocation.
What We Know vs. Don’t
Exposure & Fix Status
The supplied source leaves several practical questions open. This matrix summarizes what is established by the post versus what remains unverified.
| Question | Status in Source | Notes |
|---|---|---|
| Exploit works on current Windows? | ✗ No | Newer Windows kernel and driver code uses user-mode accessors that block the described technique. |
| Which Windows builds are protected? | ~ Unspecified | Source does not identify affected or protected releases, or when the mitigation took effect. |
| Has Avast patched the driver? | ~ Unknown | No affected driver versions or vendor fixes are stated; consult current Avast advisories. |
| Exploited in the wild? | ✗ No evidence | The source presents a research exploit path and reports no real-world attacks. |
| Publication timeline? | ~ Not stated | The source does not say when the research or post was published. |
| Independent verification of exploit? | ✗ Not verified | Claims are the researchers’ technical account; the source does not independently verify them. |
Key Questions
Frequently Asked
Quick answers drawn strictly from the supplied source material.
What is CVE-2025-13032?
Safa Team describes it as a double-fetch vulnerability in an Avast kernel driver that could cause a kernel pool overflow when a user-controlled length changed between reads.
What could the flaw enable?
The researchers pursued an arbitrary kernel read/write capability and local privilege escalation. The post presents this as an exploit path, not evidence of attacks in the wild.
Does the technique still work on Windows?
No. The authors say newer Windows kernel and driver accessors prevent the specific technique described. The source does not list the affected or protected Windows builds.
Has Avast patched the driver?
The supplied source does not state whether Avast issued a driver update or identify affected driver versions. Readers should consult current Avast advisories for that status.
A Race in Kernel Memory Handling
The report illustrates how a flaw in handling user-controlled memory can become a route from an application-level request to kernel memory corruption. Because kernel code operates with high privileges, a successful local privilege escalation could let a user with existing access gain greater control over a Windows system. The post describes a research exploit path, however, and does not show that attackers used it or establish the practical exposure of Avast customers.
The mitigation detail also matters: exploitability can depend on the behavior of the operating system as well as the vulnerable driver. According to the authors, newer Windows access checks disrupt their technique. Readers assessing exposure would still need information about affected driver versions, relevant Windows builds, and any vendor fixes, none of which is provided in the supplied material.
From Bug Finding to Exploit
This is the second and final installment in Safa Team’s Avast research. The authors describe the first part as covering entry into and escape from the Avast antivirus sandbox, while this post focuses on exploiting CVE-2025-13032. The source links to the first installment but does not summarize its findings in detail.
The post explains that the overflow occurs in paged pool, an area of kernel memory used for data that may be paged out. It says the Windows Segment Heap uses different allocation approaches for small and larger allocations, which affects how researchers arrange nearby objects. Against that background, the authors selected an I/O Ring registered-buffer array because its allocation could be sized through user registration and its pointers were stored in the affected pool.
Exposure and Fix Status
The supplied source does not state when the research or post was published, which Avast driver versions are affected, or whether Avast issued a fix. It also does not identify the Windows versions that include the mitigation or detail how users can confirm it is active. The authors’ account describes a local exploit technique, but provides no evidence in the supplied material that it was used in real-world attacks.
Check Vendor and Windows Updates
The post presents itself as the final part of this research and points readers to a video for further details about the Windows mitigation. For practical status, readers will need current information from Avast and Microsoft on affected driver versions, fixes, and Windows build coverage. The source does not announce a further research milestone or provide a timeline for those details.
Key Questions
What is CVE-2025-13032 in this report?
Safa Team describes it as a double-fetch vulnerability in an Avast kernel driver that could cause a kernel pool overflow when a user-controlled length changed between reads.
What did the researchers say the flaw could enable?
The post says the researchers pursued an arbitrary kernel read/write capability and local privilege escalation. It presents this as an exploit path, not evidence of attacks in the wild.
Does the post say the technique still works on Windows?
No. The authors say newer Windows kernel and driver accessors prevent the specific technique described. The supplied source does not list the affected or protected Windows builds.
Has Avast patched the driver?
The supplied source does not state whether Avast issued a driver update or identify affected driver versions. Readers should consult current Avast advisories for that status.
Source: Hacker News
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
