logo

Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell

ID: 7cc017e2-eca7-54b6-a6b7-5e8b4bc7af6d

STIX ID: report--7cc017e2-eca7-54b6-a6b7-5e8b4bc7af6d

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

Author: Divya

...
...

A public GitHub proof-of-concept claims a local privilege escalation zero-day in GenDigital’s Avast Antivirus (tested on Windows 11 25H2) that abuses the Avast Sandbox to dump the SAM registry hive and obtain an NT AUTHORITY\SYSTEM shell. The repository contains C/C++ source, project files, and compiled x64 artifacts, increasing the risk that adversaries with local code execution could escalate privileges; defenders are advised to monitor for suspicious Avast-related child processes, SYSTEM-level command interpreters, access to HKLM\SAM/HKLM\SYSTEM, inventory deployed Avast versions, restrict local execution, and apply vendor mitigations when available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.