• Sources: primary, discussion
  • Summary: The writeup, dated 2026-09-18, is the second part of a series on the Avast antivirus sandbox and covers CVE-2025-13032, a double fetch in the product's kernel driver. The exploit corrupts IORing registered buffers to reach SYSTEM on Windows 11, and the full chain is published. The post states that the current Windows kernel user-mode accessors prevent the technique it describes, and it names no affected driver version range.
  • Why it matters: The vulnerable code is a security product's own kernel driver, which sits on the trusted path of every endpoint that installs it.

send feedback on this story