How To Enter And Break Out Of The Avast Antivirus Sandbox: Part 2
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Safa Team’s second and final post on CVE-2025-13032 describes how researchers exploited a double-fetch flaw in an Avast kernel driver to cause a pool overflow and pursue local privilege escalation. The post says a newer Windows kernel mitigation prevents the specific technique; the source does not establish the vulnerability’s current patch status or whether it was exploited outside research.

Safa Team has published the second and final part of its research into CVE-2025-13032, describing how researchers exploited a double-fetch flaw in an Avast kernel driver on an up-to-date Windows 11 system at the time of their finding. The researchers say the flaw could trigger a kernel pool overflow and support a local privilege escalation; they also note that a newer Windows mitigation prevents the specific technique described.

The bug involved a user-supplied UNICODE_STRING whose Length field the driver read more than once. According to the post, the driver used one read to size a kernel pool allocation and a later read to determine how much data to copy. If another thread changed the field between those operations, the copy could exceed the allocation and overflow the pool. The researchers say their proof of concept repeatedly changed the value while issuing the relevant driver request, relying on the timing of the two reads.

The post says the researchers sought to turn that overflow into an arbitrary kernel read and write capability, then use it for local privilege escalation. It identifies an I/O Ring object’s registered-buffer array as the target for corruption: the researchers said the array is allocated in paged pool, the same pool affected by the overflow, and its size can be controlled by the number of registered buffers. They describe corrupting a pointer in the array as a route to the read/write capability. These are the researchers’ technical claims; the supplied source does not independently verify the exploit or report exploitation in the wild.

Safa Team’s post also says current Windows kernel and driver code uses user-mode accessors to validate kernel access to user memory. The authors say this change blocks the exploitation method in their write-up. That statement concerns the described technique; the source does not specify which Windows releases include the mitigation, when it took effect, or whether Avast separately changed its driver.

At a glance
reportWhen: Published after the initial research in…
The developmentSafa Team published the second and final installment of its research describing an exploit path for CVE-2025-13032 in an Avast kernel driver.
How To Enter And Break Out Of The Avast Antivirus Sandbox: Part 2

Vulnerability Research Brief · Part 2 of 2

How To Enter And Break Out Of The Avast Antivirus Sandbox: Part 2

Safa Team’s second and final post on CVE-2025-13032 describes how researchers exploited a double-fetch flaw in an Avast kernel driver to cause a pool overflow and pursue local privilege escalation — and why a newer Windows kernel mitigation blocks the specific technique.

Double-Fetch
Flaw class in user-supplied UNICODE_STRING
Pool Overflow
Kernel paged pool corruption via racing Length reads
LPE Goal
Arbitrary kernel read / write capability
Windows 11
Up-to-date target system at time of research
2 Reads
One sizes allocation, one sizes copy
Paged Pool
Overflow location & target object pool
1 Mitigation
Newer Windows accessors block the technique

Exploit Chain Overview

From Bug Finding to Exploit

Part 1 covered entry into and escape from the Avast antivirus sandbox; this installment focuses on weaponizing CVE-2025-13032. The visual chain below summarizes the researchers’ described path from a user-mode request to privilege escalation.

1

Sandbox Escape

Part 1 of the research covered entering and escaping the Avast antivirus sandbox.

2

Double Fetch

A user-supplied UNICODE_STRING’s Length field is read twice by the driver.

3

Pool Overflow

A racing thread shrinks the Length between reads, so the copy exceeds the allocation.

4

Corrupt I/O Ring

Overflow targets a registered-buffer array’s pointer in the same paged pool.

5

Privilege Escalation

Corrupted pointer yields arbitrary kernel read/write, enabling local privilege escalation.

The Race Window

A Race in Kernel Memory Handling

The driver used one read of the Length field to size a kernel pool allocation and a later read to determine how much data to copy. The proof of concept repeatedly changed the value from another thread while issuing the driver request, relying on the timing between the two reads.

Read #1
Allocates pool
Race Window
Thread mutates Length
Read #2
Copy overflows
Why it matters: Kernel code operates with high privileges, so a successful local privilege escalation could let a user with existing access gain greater control over a Windows system. This describes a research exploit path — the source does not show attackers used it or establish the practical exposure of Avast customers.

Technical Mechanics

Inside the Overflow

The overflow occurs in paged pool — kernel memory used for data that may be paged out. The Windows Segment Heap’s different allocation strategies for small and larger allocations affect how researchers arranged nearby objects.

Root Cause

Double-Fetched Length

A UNICODE_STRING supplied from user mode has its Length field read more than once by the Avast kernel driver. If another thread changes the field between the two operations, the copy can exceed the allocation.

Target Selection

I/O Ring Buffer Array

An I/O Ring object’s registered-buffer array is allocated in paged pool — the same pool affected by the overflow — and its size can be controlled by the number of registered buffers, enabling precise heap grooming.

Payoff

Arbitrary R/W via Pointer

Corrupting a pointer in the registered-buffer array serves as the route to an arbitrary kernel read and write capability, which the researchers then used toward local privilege escalation.

Heap Landscape

Controlling the Paged Pool

The Windows Segment Heap uses different allocation approaches depending on size — a factor the researchers leveraged when arranging objects near the vulnerable allocation.

Segment Heap · Small Allocations
Segregated bins
Segment Heap · Larger Allocations
Dedicated allocation path
I/O Ring Array · Size Controlled by User Registration
Attacker-sized via buffer count

What We Know vs. Don’t

Exposure & Fix Status

The supplied source leaves several practical questions open. This matrix summarizes what is established by the post versus what remains unverified.

Question Status in Source Notes
Exploit works on current Windows? ✗ No Newer Windows kernel and driver code uses user-mode accessors that block the described technique.
Which Windows builds are protected? ~ Unspecified Source does not identify affected or protected releases, or when the mitigation took effect.
Has Avast patched the driver? ~ Unknown No affected driver versions or vendor fixes are stated; consult current Avast advisories.
Exploited in the wild? ✗ No evidence The source presents a research exploit path and reports no real-world attacks.
Publication timeline? ~ Not stated The source does not say when the research or post was published.
Independent verification of exploit? ✗ Not verified Claims are the researchers’ technical account; the source does not independently verify them.

Key Questions

Frequently Asked

Quick answers drawn strictly from the supplied source material.

What is CVE-2025-13032?

Safa Team describes it as a double-fetch vulnerability in an Avast kernel driver that could cause a kernel pool overflow when a user-controlled length changed between reads.

What could the flaw enable?

The researchers pursued an arbitrary kernel read/write capability and local privilege escalation. The post presents this as an exploit path, not evidence of attacks in the wild.

Does the technique still work on Windows?

No. The authors say newer Windows kernel and driver accessors prevent the specific technique described. The source does not list the affected or protected Windows builds.

Has Avast patched the driver?

The supplied source does not state whether Avast issued a driver update or identify affected driver versions. Readers should consult current Avast advisories for that status.

A Race in Kernel Memory Handling

The report illustrates how a flaw in handling user-controlled memory can become a route from an application-level request to kernel memory corruption. Because kernel code operates with high privileges, a successful local privilege escalation could let a user with existing access gain greater control over a Windows system. The post describes a research exploit path, however, and does not show that attackers used it or establish the practical exposure of Avast customers.

The mitigation detail also matters: exploitability can depend on the behavior of the operating system as well as the vulnerable driver. According to the authors, newer Windows access checks disrupt their technique. Readers assessing exposure would still need information about affected driver versions, relevant Windows builds, and any vendor fixes, none of which is provided in the supplied material.

From Bug Finding to Exploit

This is the second and final installment in Safa Team’s Avast research. The authors describe the first part as covering entry into and escape from the Avast antivirus sandbox, while this post focuses on exploiting CVE-2025-13032. The source links to the first installment but does not summarize its findings in detail.

The post explains that the overflow occurs in paged pool, an area of kernel memory used for data that may be paged out. It says the Windows Segment Heap uses different allocation approaches for small and larger allocations, which affects how researchers arrange nearby objects. Against that background, the authors selected an I/O Ring registered-buffer array because its allocation could be sized through user registration and its pointers were stored in the affected pool.

Exposure and Fix Status

The supplied source does not state when the research or post was published, which Avast driver versions are affected, or whether Avast issued a fix. It also does not identify the Windows versions that include the mitigation or detail how users can confirm it is active. The authors’ account describes a local exploit technique, but provides no evidence in the supplied material that it was used in real-world attacks.

Check Vendor and Windows Updates

The post presents itself as the final part of this research and points readers to a video for further details about the Windows mitigation. For practical status, readers will need current information from Avast and Microsoft on affected driver versions, fixes, and Windows build coverage. The source does not announce a further research milestone or provide a timeline for those details.

Key Questions

What is CVE-2025-13032 in this report?

Safa Team describes it as a double-fetch vulnerability in an Avast kernel driver that could cause a kernel pool overflow when a user-controlled length changed between reads.

What did the researchers say the flaw could enable?

The post says the researchers pursued an arbitrary kernel read/write capability and local privilege escalation. It presents this as an exploit path, not evidence of attacks in the wild.

Does the post say the technique still works on Windows?

No. The authors say newer Windows kernel and driver accessors prevent the specific technique described. The supplied source does not list the affected or protected Windows builds.

Has Avast patched the driver?

The supplied source does not state whether Avast issued a driver update or identify affected driver versions. Readers should consult current Avast advisories for that status.

Source: Hacker News

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Purple Teaming: Blending Offense and Defense for 360° VisibilityBusiness

Growing your cybersecurity with purple teaming unites offense and defense for comprehensive visibility—discover how this approach can transform your security strategy today.

Watch Full Ethical Hacking: Scanning Networks – Improve Your Security

Hone your cybersecurity skills with ethical hacking techniques for network scanning – discover how to fortify your defenses!

Why Ethical Hacking Labs Need Clear Rules to Stay Useful

Protection and focus in ethical hacking labs rely on clear rules, ensuring safety and professionalism—discover why these guidelines are essential for success.

What Beginners Should Learn Before Touching Kali Linux

An essential foundation in cybersecurity, networking, and ethics is crucial before diving into Kali Linux to ensure responsible and effective hacking practices.