CVE-2025-13032
Avast Antivirus vulnerability analysis and mitigation

Overview

CVE-2025-13032 is a double-fetch Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in the sandbox kernel driver of Avast and AVG Antivirus on Windows. It allows a local attacker with low privileges to escalate privileges via a pool overflow. All versions prior to 25.3 are affected. The vulnerability was published on November 11, 2025, and a patch was made available in version 25.3. It carries a CVSS v3.1 base score of 7.8 (High) (Red Hat Advisory, Gen Digital).

Technical details

The root cause is a double-fetch TOCTOU race condition (CWE-367) in the sandbox kernel driver component of Avast and AVG Antivirus. In a double-fetch scenario, the kernel driver reads a user-supplied value twice from user-space memory without proper synchronization; an attacker can race between the two reads to substitute a different value, causing a pool overflow (CWE-787) that corrupts kernel memory. Exploitation requires only low-privileged local access and no user interaction, making it a straightforward local privilege escalation primitive. The attack vector is local, with low attack complexity (Red Hat Advisory, Cybernoz).

Impact

Successful exploitation grants a low-privileged local attacker full control over the affected Windows system, compromising confidentiality, integrity, and availability at the highest level. An attacker can read sensitive system data, modify system files and configurations, and disrupt or fully compromise system operations. Because the vulnerability resides in a kernel driver, exploitation results in kernel-level code execution, enabling persistence, credential theft, and lateral movement within a network (Red Hat Advisory, GBHackers).

Exploitation steps

  1. Reconnaissance: Identify target Windows systems running Avast or AVG Antivirus versions prior to 25.3, which include the vulnerable sandbox kernel driver.
  2. Gain local access: Obtain a low-privileged local user account on the target system (e.g., via phishing, credential reuse, or existing foothold).
  3. Trigger the double-fetch race: Craft a malicious user-space application that interacts with the vulnerable sandbox kernel driver's IOCTL interface, supplying a controlled buffer. Simultaneously race a second thread to modify the buffer contents between the driver's first and second reads of the user-space value.
  4. Cause pool overflow: The inconsistency between the two fetched values causes the kernel driver to perform an out-of-bounds write into the kernel pool, corrupting adjacent memory structures.
  5. Achieve privilege escalation: Leverage the corrupted kernel memory (e.g., overwriting a token or process structure) to elevate the attacker's process to SYSTEM-level privileges, enabling full control of the host (Red Hat Advisory, GBHackers).

Indicators of compromise

  • Process: Unexpected processes running with SYSTEM privileges spawned from low-privileged user sessions; unusual child processes of the Avast/AVG sandbox kernel driver process.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 – Special privileges assigned to new logon) for non-administrative accounts; kernel crash dumps or bugcheck events (BSOD) related to pool corruption.
  • File System: New or modified files in system directories (e.g., %SystemRoot%\System32) created by non-administrative accounts; unexpected scheduled tasks or services installed post-exploitation.
  • Network: Outbound connections from SYSTEM-level processes to unusual external IP addresses, potentially indicating post-exploitation lateral movement or C2 activity (GBHackers).

Mitigation and workarounds

The primary remediation is to update Avast or AVG Antivirus to version 25.3 or later, which contains the fix for this vulnerability (Gen Digital). As interim measures, administrators should audit and restrict local user permissions to limit the attack surface, and monitor systems for unusual privilege escalation activity. Implementing additional endpoint detection controls and ensuring automatic updates are enabled will help reduce exposure.

Community reactions

Heise reported on the vulnerability being quietly patched by Avast/AVG, noting the significance of a critical security flaw in a widely deployed security product (Heise). The Hacker News included it in a weekly security recap, and it appeared in Reddit's CVEWatch trending CVE lists for multiple days in December 2025, indicating notable community interest (The Hacker News). Security news outlets including GBHackers, CyberSecurityNews, and CyberPress covered the disclosure, highlighting the risk of privilege escalation via a trusted security product's kernel driver (GBHackers, CyberSecurityNews).

Additional resources


SourceThis report was generated using AI

Related Avast Antivirus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-3500CRITICAL9.8
  • Avast Antivirus logoAvast Antivirus
  • cpe:2.3:a:avast:antivirus
NoYesDec 01, 2025
CVE-2025-8351HIGH7.8
  • Avast Antivirus logoAvast Antivirus
  • cpe:2.3:a:avast:antivirus
NoYesDec 01, 2025
CVE-2025-13032HIGH7.8
  • Avast Antivirus logoAvast Antivirus
  • cpe:2.3:a:avast:antivirus
NoYesNov 11, 2025
CVE-2025-7007HIGH7.5
  • Avast Antivirus logoAvast Antivirus
  • cpe:2.3:a:avast:antivirus
NoNoDec 01, 2025
CVE-2024-9484MEDIUM5.5
  • AVG Antivirus logoAVG Antivirus
  • cpe:2.3:a:avast:antivirus
NoYesOct 04, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management