Double Fetch Vulnerability in Avast and AVG Windows Anti Rootkit Driver
CVE-2022-26522

7.8HIGH

Key Information:

Vendor

Avast

Vendor
CVE Published:
8 May 2026

What is CVE-2022-26522?

A double fetch vulnerability exists in the socket connection handler of aswArPot.sys within the Avast and AVG Windows Anti Rootkit driver prior to version 22.1. This flaw allows local attackers to execute arbitrary code in kernel mode, potentially leading to severe impacts, including memory corruption and denial of service, which can crash the operating system. Proper updates and system defenses are crucial to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.