PT-2025-46368 · Avg+1 · Avg Antivirus+1

Safa Team

·

Published

2025-11-11

·

Updated

2025-12-07

·

CVE-2025-13032

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avast/AVG Antivirus versions prior to 25.3
Description A double fetch race condition exists in the Avast/AVG kernel sandbox driver on Windows. This condition allows a local attacker to escalate privileges through a pool overflow. The issue involves a break-in and escape from the antivirus sandbox, potentially leading to a SYSTEM token heist.
Recommendations Update Avast/AVG Antivirus to version 25.3 or later.

Fix

LPE

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2025-13032

Affected Products

Avg Antivirus
Avast Antivirus