Improper Permissions in Avast Sandbox Driver Leading to SYSTEM Escalation
CVE-2026-82964

8.8HIGH

What is CVE-2026-82964?

A flaw in the Avast sandbox minifilter driver allows a local, low-privileged attacker operating within the sandbox environment to escape file isolation. This vulnerability arises from improper handling of security descriptors when virtualizing files. By neglecting to apply necessary permissions, sensitive files can become accessible, enabling the attacker to alter security attributes and potentially extract critical data—such as NTLM password hashes from the SAM database—and execute arbitrary code with elevated SYSTEM privileges. The issue is compounded by the lack of specific security callbacks, leading to broader risks in system security.

Affected Version(s)

Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security Windows 0

AVG Antivirus Free, AVG Internet Security, AVG Ultimate Windows 0

Norton Antivirus Plus, Norton 360 Standard, Norton 360 Deluxe, Norton 360 Advanced Windows 0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

MSNightmare, independent security researcher
.