
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13032 is a double-fetch Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in the sandbox kernel driver of Avast and AVG Antivirus on Windows. It allows a local attacker with low privileges to escalate privileges via a pool overflow. All versions prior to 25.3 are affected. The vulnerability was published on November 11, 2025, and a patch was made available in version 25.3. It carries a CVSS v3.1 base score of 7.8 (High) (Red Hat Advisory, Gen Digital).
The root cause is a double-fetch TOCTOU race condition (CWE-367) in the sandbox kernel driver component of Avast and AVG Antivirus. In a double-fetch scenario, the kernel driver reads a user-supplied value twice from user-space memory without proper synchronization; an attacker can race between the two reads to substitute a different value, causing a pool overflow (CWE-787) that corrupts kernel memory. Exploitation requires only low-privileged local access and no user interaction, making it a straightforward local privilege escalation primitive. The attack vector is local, with low attack complexity (Red Hat Advisory, Cybernoz).
Successful exploitation grants a low-privileged local attacker full control over the affected Windows system, compromising confidentiality, integrity, and availability at the highest level. An attacker can read sensitive system data, modify system files and configurations, and disrupt or fully compromise system operations. Because the vulnerability resides in a kernel driver, exploitation results in kernel-level code execution, enabling persistence, credential theft, and lateral movement within a network (Red Hat Advisory, GBHackers).
%SystemRoot%\System32) created by non-administrative accounts; unexpected scheduled tasks or services installed post-exploitation.The primary remediation is to update Avast or AVG Antivirus to version 25.3 or later, which contains the fix for this vulnerability (Gen Digital). As interim measures, administrators should audit and restrict local user permissions to limit the attack surface, and monitor systems for unusual privilege escalation activity. Implementing additional endpoint detection controls and ensuring automatic updates are enabled will help reduce exposure.
Heise reported on the vulnerability being quietly patched by Avast/AVG, noting the significance of a critical security flaw in a widely deployed security product (Heise). The Hacker News included it in a weekly security recap, and it appeared in Reddit's CVEWatch trending CVE lists for multiple days in December 2025, indicating notable community interest (The Hacker News). Security news outlets including GBHackers, CyberSecurityNews, and CyberPress covered the disclosure, highlighting the risk of privilege escalation via a trusted security product's kernel driver (GBHackers, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."