TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Safetec published the second and final part of its Avast research, describing how researchers exploited CVE-2025-13032, a double-fetch flaw in an Avast kernel driver, to pursue local privilege escalation on an up-to-date Windows 11 system at the time of discovery. The post says newer Windows kernel and driver accessors prevent the described technique; it does not specify the affected Avast versions, patch timeline or whether the flaw was exploited outside research.
Safetec has published the second and final part of its research into CVE-2025-13032, describing how researchers exploited a double-fetch flaw in an Avast kernel driver to create a kernel pool overflow and pursue local privilege escalation on an up-to-date Windows 11 system at the time of the finding. The researchers say a newer Windows kernel and driver mitigation blocks the technique described in the post, though the write-up does not identify which Avast versions were affected or give a patch timeline.
The flaw involves a user-supplied Windows UNICODE_STRING. According to Safetec’s code analysis, the driver reads the string’s Length field more than once: it uses one value to allocate kernel memory and later uses another to copy data. A second thread can change the shared value between those reads. If the allocation uses a small length and the copy uses a much larger one, the copy can exceed the allocated buffer and overflow the paged pool.
Safetec says its demonstration repeatedly toggled the field between a safe value and a larger one while the main thread called the vulnerable input/output control request. The researchers describe the timing window as narrow but say it could be won within a modest number of iterations. The post’s stated objective was to turn the overflow into an arbitrary kernel read/write primitive and use it for local privilege escalation; that is the researchers’ account of their exploit, not evidence that attackers used it in the wild.
The write-up identifies the Windows I/O Ring object’s registered-buffer array as its corruption target. Safetec says the array resides in paged pool, its size can be controlled by registering buffers, and corrupting one pointer can provide the desired read/write capability. The article describes this as the researchers’ target and rationale; it does not provide a full patch history or detail the specific Avast product releases involved.
A Driver Flaw With Kernel Reach
A bug in an antivirus driver matters because kernel code runs with broad system privileges. If a local attacker can reach the vulnerable driver interface and reliably exploit the overflow, the resulting kernel read and write access could undermine protections that operate at the user level and support a local privilege escalation. The post documents a research technique and goal; it does not establish that the flaw was used in attacks or that it was remotely exploitable.
The researchers’ choice of an I/O Ring object illustrates how a memory corruption bug can be shaped into a more powerful primitive. According to the post, the registered-buffer pointers offer a controllable target in the same pool as the overflow. That makes the report relevant to defenders reviewing driver attack surface and to Windows maintainers evaluating protections for accesses to user memory.
Safetec also says the technique is blocked in the latest Windows kernel and drivers through user-mode accessors, which check kernel access to user-mode memory at each access. This is a statement about the described exploitation method. The article does not claim that the underlying Avast defect was repaired by that mitigation, nor does it establish that all exploitation paths are covered.
From Double Fetch to I/O Ring
This is the second and final part of Safetec’s Avast research. The authors say the post recaps the flaw and focuses on exploiting it on an up-to-date Windows 11 system at the time they found it. They link to a first part covering entry into and breaking out of Avast’s antivirus sandbox, but the source material here does not recount that part’s findings in detail.
The technical issue is a race between two reads of mutable user memory. The post says the driver first probes the supplied string and then passes it to code that allocates space using its reported length. The code subsequently reads the length again to copy the contents. Because the user can change that field, the two operations may use inconsistent sizes. Safetec describes the result as a paged-pool overflow.
To explain why the chosen target could work, the researchers discuss Windows pool allocation. They say allocation behavior differs by size class, with the Low Fragmentation Heap handling smaller allocations and the Variable Size allocator serving larger ones. Their write-up says the registered-buffer array’s user-controlled size helped them arrange a suitable allocation. The detail provides context for the exploit strategy, but the post does not establish that the same arrangement works across every Windows build.
“This blogpost is the second and final part of our Avast research.”
— Safetec researchers
Affected Versions and Fixes
The provided write-up does not state which Avast versions contain the flaw, when a vendor fix was released, or whether Avast issued an advisory. It also does not give a specific date for publication or identify the Windows build used in the demonstration. The phrase “up-to-date Windows 11” refers to the system at the time of the finding, not necessarily current releases.
The researchers say the newer Windows mitigation blocks their described technique, but the source does not specify the minimum Windows version containing it or explain whether it applies to systems without the relevant kernel and driver changes. The account is a research report; it offers no evidence in the supplied material of in-the-wild exploitation, affected user numbers, or attacks against particular organizations.
Clarifying Fix and Mitigation Status
The next useful developments would be a vendor advisory identifying affected Avast releases and any remediation, alongside version-specific guidance for Windows users. Safetec points readers to Microsoft material on user-mode accessors and a separate technical video for more detail on the mitigation. Until those details are tied to particular product and operating-system versions, the scope of exposure and the protection available on individual systems remain uncertain.
Key Questions
What is CVE-2025-13032?
Safetec describes it as a double-fetch vulnerability in an Avast kernel driver. The driver can read a user-supplied string length once for allocation and again for copying, allowing the values to differ.
What could the flaw allow?
The researchers say the mismatch can cause a kernel pool overflow. Their exploit aimed to turn that into arbitrary kernel read/write access and local privilege escalation.
Does the report say attackers used it?
No. The supplied research describes a proof-of-concept exploitation approach, but does not report exploitation in the wild.
Does the article identify affected Avast versions?
No. The source material does not list affected product versions or provide a vendor patch timeline.
What mitigation do the researchers describe?
They say newer Windows kernel and driver user-mode accessors check each kernel access to user memory and prevent the technique described in the post. The write-up does not specify the exact Windows versions covered.
Source: Hacker News
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
