TL;DR
Get the latest gadgets delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Safa Team’s second and final post on Avast’s antivirus sandbox describes how researchers exploited CVE-2025-13032, a double-fetch flaw in an Avast kernel driver, to produce a kernel pool overflow. The authors say a newer Windows mitigation prevents the technique they describe; the post does not establish whether the underlying driver flaw has been fixed.
Safa Team has published the second and final part of its research into Avast’s antivirus sandbox, describing how researchers exploited CVE-2025-13032, a double-fetch flaw in an Avast kernel driver, on a Windows 11 system. The post says the flaw could cause a kernel pool overflow, while warning that a newer Windows mitigation prevents the specific exploitation technique described.
The researchers describe a driver routine that reads the Length field of a user-supplied Unicode string more than once. The first read determines how much kernel memory is allocated; a later read determines how many bytes are copied. If the value changes between those operations, the copy can exceed the allocation, causing an overflow in paged kernel pool memory.
The post says the researchers used the flaw as a route toward arbitrary kernel read and write, with the stated goal of local privilege escalation. It identifies a Windows I/O Ring object’s registered-buffer array as the corruption target: the array is allocated in paged pool, and its size depends on how many buffers are registered. The authors say changing a pointer in that array can provide the access primitive they sought.
Safa Team reports that the race could be won within a modest number of iterations, but does not provide a success rate or a reproducible benchmark. Its post describes the researcher’s exploitation approach and says the technique was tested on an up-to-date Windows 11 system at the time of the finding. The source material does not give the testing build number or the dates of the test.
A Kernel Flaw With Local Escalation Risk
A flaw in an antivirus kernel driver matters because the driver operates with access to sensitive system memory. According to the researchers, exploiting this bug could turn a faulty string-handling operation into kernel-level read and write access, potentially allowing a local attacker to raise privileges. The post describes a research result; it does not report that attackers used the flaw in the wild.
The account also highlights how a small programming error can interact with Windows memory allocation and object handling. The authors’ choice of an I/O Ring buffer array shows why user-controlled allocation sizes and persistent pointers can matter when analyzing memory corruption. That technical relevance does not, by itself, establish the bug’s current exposure or risk to Avast users.
From Sandbox Entry to Exploitation
This is the second and final installment of Safa Team’s research on entering and breaking Avast’s antivirus sandbox. The first part, linked from the follow-up post, covers the earlier stage of the research. The second post shifts focus to exploiting CVE-2025-13032 in the Avast kernel driver.
The authors place the bug in Windows paged pool, a region used for kernel allocations that do not need to remain resident in physical memory at all times. They note that Windows 10 version 19H1 introduced the Segment Heap for pool allocations, with separate allocation strategies for smaller and larger objects. This allocator background explains the researchers’ discussion of arranging allocations, but the post’s key finding is the double fetch in the driver.
The article also points to public research on Windows pool exploitation and prior public use of I/O Ring objects as exploitation targets. Those references provide technical context for the authors’ target selection; they do not independently confirm the Avast bug’s status or the availability of a fix.
The Driver’s Current Status
The post does not specify whether Avast has released a driver update addressing CVE-2025-13032, when the vulnerability was reported to the company, or whether the flaw remains present in current Avast software. It also does not give the exact Windows build affected in testing or the version in which the cited mitigation became available.
The authors say the newer mitigation blocks their described technique, but that statement does not establish that every possible exploitation route is prevented or that the underlying driver bug has been removed. The post reports a research finding and does not document confirmed exploitation outside the research.
Patch and Mitigation Details
The next details readers would need are confirmation from Avast about the driver’s remediation status and from Microsoft about which Windows versions include the cited user-mode accessor checks. Until those details are available, the report supports a narrower conclusion: Safa Team describes a kernel overflow and a route to privilege escalation on its test system, while saying a newer Windows mitigation stops the technique it used.
Key Questions
What is CVE-2025-13032?
It is the identifier used in Safa Team’s report for a double-fetch vulnerability in an Avast kernel driver. The authors say changing a user-supplied string length between reads could cause a kernel pool overflow.
What impact did the researchers report?
The researchers say they used the overflow toward an arbitrary kernel read and write primitive, with local privilege escalation as their goal. The post describes research and does not report in-the-wild attacks.
Does the report say Avast fixed the flaw?
No fix status is given in the supplied post. It says a newer Windows mitigation prevents the described exploitation technique, which is a separate claim from whether Avast corrected the driver flaw.
Why did the researchers target an I/O Ring object?
The authors say its registered-buffer array is allocated in paged pool and its size can be controlled by the number of registered buffers. They report that corrupting one pointer in the array was sufficient for their intended kernel access primitive.
Source: Hacker News
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
