以下是该漏洞描述的中文翻译: Windows 上 Avast 沙箱 mini 过滤驱动(aswSnx.sys)中权限保留机制存在缺陷,使得在沙箱内运行的本地低权限攻击者能够突破文件隔离,并将权限提升至 SYSTEM 级别。 当沙箱对文件进行虚拟化时,会复制原始安全描述符(security descriptor)。然而,驱动在打开虚拟化目标对象时仅使用了 和 权限,遗漏了 。因此,所有尝试应用原始 DACL 的操作均失败,且这些失败被静默丢弃,导致敏感文件的虚拟化副本保留了过于宽松的权限。此外,由于驱动在 回调中未针
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gen Digital | Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security | < 26.8 |
affected |
| Gen Digital | AVG Antivirus Free, AVG Internet Security, AVG Ultimate | < 26.8 |
affected |
| Gen Digital | Norton Antivirus Plus, Norton 360 Standard, Norton 360 Deluxe, Norton 360 Advanced | < 26.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Gen Digital | Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security | 0 ~ 26.8 | - |
|
| Gen Digital | AVG Antivirus Free, AVG Internet Security, AVG Ultimate | 0 ~ 26.8 | - |
|
| Gen Digital | Norton Antivirus Plus, Norton 360 Standard, Norton 360 Deluxe, Norton 360 Advanced | 0 ~ 26.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet