DigiNews

Tech Watch by Johan Denoyer

← Back to articles

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

Quality: 8/10 Relevance: 9/10

Summary

Technical deep-dive into CVE-2025-13032, detailing Avast kernel driver double-fetch exploit, paged pool overflow, and a chain to arbitrary kernel read/write and SYSTEM privilege escalation. Includes heap spraying, MDL-based leaks, and token theft, with patch guidance.

🚀 Service construit par Johan Denoyer