Cyber Security News

10-Year-Old Flaws With Avast and AVG Antivirus Let Attacker to Escalate Privileges

SentinelOne’s Kasif Dekel has discovered and publicly disclosed two new high-severity security vulnerabilities in Avast and AVG antivirus products.

The two vulnerabilities are tracked as CVE-2022-26522 and CVE-2022-26523 affecting a legitimate driver that is used by both Avast and AVG AV solutions.

Here’s what Kasif Dekel stated:-

“These vulnerabilities allow attackers to escalate privileges enabling them to disable security products, overwrite system components, corrupt the operating system, or perform malicious operations unimpeded.”

Bugs have been reported in the anti-rootkit kernel driver named aswArPot.sys, an authenticated version of “Avast Anti-Rootkit” from AVAST Software. As of June 12, 2012, Avast 12.1, which is effectively the current version of the driver, has been released.

There is the possibility that a malicious attacker could take advantage of these vulnerabilities to escalate privileges and likely disable antivirus applications.

The security flaw relates to a socket connection handler in the kernel driver, which could give non-administrator users privilege escalation. Therefore, the problem could possibly lead to the blue screen of death error and crash the operating system.

Flaws

It appears that the vulnerability (CVE-2022-26522) resides in a routine in a socket connection handler that is used by the kernel driver aswArPot.sys. And hereby instigating a socket connection it is possible to trigger the issue.

As for the second vulnerability, it is also tracked as CVE-2022-26523 and lies in the aswArPot+0xbb94 function just like the first one.

There is a possibility that the flaws can lead to a second-stage browser attack that allows the exploitation of the sandbox to escape flaws.

Mitigation

Millions of users all over the world are affected by these highly severe vulnerabilities. Users of Avast and AVG will be able to automatically receive the new patch (version 22.1) during the coming weeks automatically. 

While the patch should be applied as soon as possible for users of on-premise or air-gapped installations.

It is a known fact that coordinated disclosure is an excellent means of preventing risks from falling into the hands of attackers. Experts have a bug bounty program that they encourage you to sign up for.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago