Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82964— Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx.sys

Quick assessment

Affected
Gen Digital Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: Windows 上 Avast 沙箱 mini 过滤驱动(aswSnx.sys)中权限保留机制存在缺陷,使得在沙箱内运行的本地低权限攻击者能够突破文件隔离,并将权限提升至 SYSTEM 级别。 当沙箱对文件进行虚拟化时,会复制原始安全描述符(security descriptor)。然而,驱动在打开虚拟化目标对象时仅使用了 和 权限,遗漏了 。因此,所有尝试应用原始 DACL 的操作均失败,且这些失败被静默丢弃,导致敏感文件的虚拟化副本保留了过于宽松的权限。此外,由于驱动在 回调中未针

CVSS 8.8 · High EPSS 0.14% · P3
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82964

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx.sys
Source: CVE Program / CVE List V5
Vulnerability Description
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened the virtualization target object with GENERIC_WRITE and FILE_WRITE_ATTRIBUTES only, omitting WRITE_DAC. Every attempt to apply the original DACL therefore failed, and the failure was discarded silently, leaving virtualized copies of sensitive files with permissive permissions. Because the IRP_MJ_CREATE callback additionally did not strip WRITE_DAC for sensitive directories, a sandboxed process could rewrite the security descriptor of a virtualized object, read the virtualized copy of the SAM database, extract local NTLM password hashes and execute code as SYSTEM. The absence of an IRP_MJ_SET_SECURITY callback in the driver's operation registration table is a related defense-in-depth gap, but it is not the control that prevents this attack.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
权限预留不恰当
Source: CVE Program / CVE List V5

Affected Products

II. Public POCs for CVE-2026-82964

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82964

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2026-82964 (1)

Proof of Concept for CVE-2026-82964 (1)

Vendor Pages for CVE-2026-82964 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-82964

No comments yet


Leave a comment