9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overflow.
AI Analysis
Double fetch vulnerability in Avast/AVG Antivirus sandbox kernel driver allowing local privilege escalation via pool overflow
Basic Information
ID
CVE-2025-13032
Source
NLOK
Published
Nov 11, 2025 at 16:16
Affected Product
Vendor
Avast
Product
(Free/Premiium/Ultimeat) Antivirus
Affected Versions
Avast (Free/Premiium/Ultimeat) Antivirus 0
Avsat One 0
AVG (Free/Inernet Security/Ultimate) Antivirus 0
Avsat One 0
AVG (Free/Inernet Security/Ultimate) Antivirus 0
CWE Classification
AI Assessment
AI Score
9.9 / 10
AI Severity
Critical
Vendor
Avast
Product
Avast/AVG Antivirus
Version
< 25.3