TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Researchers at Safa Team published the second and final part of their Avast security research, describing how they exploited CVE-2025-13032, a double-fetch flaw in an Avast kernel driver. They report that a newer Windows kernel and driver mitigation prevents the technique described in the post; the article does not detail the vulnerability’s patch status or affected Avast versions.
Security researchers at Safa Team have published the second and final part of their research into CVE-2025-13032, describing how a double-fetch flaw in an Avast kernel driver could be exploited on a Windows 11 system. The report says a newer Windows kernel and driver mitigation prevents the specific exploitation technique discussed, while leaving the vulnerability’s patch status and affected product versions unspecified.
The researchers describe the flaw as a double-fetch vulnerability: the driver reads a user-supplied string length more than once while handling a request. In the reported scenario, the length used to allocate kernel memory could differ from the length later used to copy data. The researchers say that discrepancy could cause a kernel pool overflow. The source presents this as the researchers’ technical analysis of the driver, rather than an independent assessment.
Safa Team says it used the flaw as the basis for a local privilege escalation demonstration on an up-to-date Windows 11 system at the time of discovery. The post describes targeting a Windows I/O Ring object to develop a kernel read/write capability. These are claims about the researchers’ demonstration; the supplied material does not include independent verification or details about a publicly available exploit.
The report’s author note says that the latest version of the Windows kernel and drivers uses user-mode accessors to check accesses to user-mode memory. According to the researchers, this mitigation blocks the exploitation technique in the post. That statement addresses the described method and does not establish whether the underlying Avast driver flaw has been fixed, which Avast products were affected, or what versions contain a fix.
Windows Mitigation Limits the Demonstration
The report illustrates how a flaw in a security product’s kernel driver can have consequences beyond the product itself. Kernel drivers operate with high privileges, so a memory-handling error can give a local attacker a path to affect operating system memory. Safa Team says its work turned the reported overflow into a local privilege escalation demonstration, raising the stakes for users and administrators responsible for keeping both security software and Windows systems current.
The researchers’ note about user-mode accessors adds an important qualification: the technique described depends on how the kernel handles user-supplied memory. If the newer checks block that method, the published demonstration may not apply to systems using the mitigation. The article does not establish how broadly those systems are deployed, whether other exploitation paths exist, or whether Avast’s driver has been updated. Those distinctions matter when assessing practical exposure.
Top picks for "escape avast antiviru"
As an affiliate, we earn on qualifying purchases.
A Two-Part Avast Research Series
This article is the second and final part of Safa Team’s research into Avast’s antivirus sandbox. The first part, linked in the report, covered entering and breaking the sandbox; this installment focuses on exploitation of CVE-2025-13032 in the kernel driver. The authors say they recap the bug and explain their Windows 11 exploitation research.
The post places the flaw in the area of kernel memory management. Its technical discussion identifies paged pool memory and the Windows I/O Ring object as relevant to the researchers’ approach. For general readers, the key point is that the reported bug involved a mismatch between memory allocated for a request and the amount later copied. The post’s detailed exploitation discussion supports the authors’ account but does not, by itself, establish the vulnerability’s current status across Avast installations.
Patch Status and Exposure Remain Unspecified
The supplied report does not state when the research was published, when Avast was notified, whether the company released a fix, or which Avast versions may be affected. It also does not say how many users or systems were exposed. The researchers’ description of a mitigation in the latest Windows version does not answer whether all supported Windows releases include it or whether it blocks other possible approaches to the vulnerability.
The report describes the researchers’ own exploitation results, but the supplied source contains no independent reproduction, vendor statement, or advisory confirming the impact. Readers should distinguish the reported demonstration from a confirmed account of exploitation in real-world attacks. The source also does not establish whether the flaw remains exploitable on currently updated systems.
Vendor and Version Details Needed
The next useful update would clarify Avast’s response: whether the company fixed the driver, which product versions were affected, and when users should update. A vendor advisory or coordinated vulnerability disclosure record could also establish notification and remediation dates. The Windows mitigation’s coverage across supported versions would help administrators determine whether it applies to their systems.
Until those details are available in the supplied material, the report stands as a technical account of a researchers’ demonstration and a stated limitation on its technique. Users and IT teams can consult Avast and Microsoft security advisories for version-specific guidance as further information becomes available.
Key Questions
What is CVE-2025-13032?
Safa Team describes CVE-2025-13032 as a double-fetch flaw in an Avast kernel driver that could lead to a kernel pool overflow.
What impact did the researchers report?
The researchers say they used the flaw in a local privilege escalation demonstration on an up-to-date Windows 11 system at the time of their finding. The supplied material does not include independent verification.
Does the report say Avast fixed the vulnerability?
No. The supplied source does not identify an Avast patch, affected product versions, or the vulnerability’s current status.
What does the Windows mitigation do?
The researchers say newer Windows user-mode accessors check kernel accesses to user-mode memory and block the specific technique described in their report. The source does not specify coverage across Windows versions.
Is there evidence of attacks using this flaw?
The supplied report describes the researchers’ exploitation work but does not say that the flaw has been used in real-world attacks.
Source: Hacker News
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
