| |
Researchers discovered and exploited CVE-2025-13032, a double-fetch vulnerability in Avast Antivirus's kernel driver that allows attackers to achieve arbitrary kernel read/write capabilities on Windows 11. The vulnerability stems from the `Length` field of a user-supplied structure being fetched multiple times, enabling a controlled pool overflow that can be weaponized to corrupt kernel objects and escalate privileges to SYSTEM. The exploitation technique involves heap spraying, kernel address leaking, and token theft, though newer Windows kernel mitigations using user-mode accessors can prevent this specific attack method.
Read Full Article →
← More Tech news