Skip to finding
§
High
Privilege — Windows
Provisional

A standard Windows user can get a SYSTEM shell through Avast's sandbox, and there is no patch.

Public code, claimed to work against fully patched Avast on patched Windows 11 25H2.

Affects

GenDigital Avast Antivirus, endpoint antivirus software on Windows desktops.

What it enables

Local SYSTEM command execution from a standard Windows account

Attacker runs code as a standard local Windows user.→↓The PoC abuses Avast Sandbox.→↓The PoC reads the Windows SAM database and starts a SYSTEM shell.
Why this matters

An ordinary local privilege escalation lands with a fix attached. This one has the code in public and nothing to install: the vendor had shipped no fix and there was no CVE when the outlets that covered it checked. The component doing the escalating is the security product itself, which is on the endpoint precisely because someone decided a standard user should not be able to do this.

Detail, proof-of-concept code and 5 sources
Required access

Run code as a standard local Windows user on a Windows host with Avast Antivirus installed.

Affected versions

Researcher claims any Avast Antivirus version; tested on fully patched Avast Antivirus with patched Windows 11 25H2.

Proof of concept

Public exploit code →

The proof of concept abuses the Avast Sandbox to read the Windows SAM database and start a SYSTEM shell. The entry requirement is code execution as a standard local user on a machine with Avast installed — no administrator, no second bug, no user prompt in the middle.

The repository claims the exploit works against fully patched Avast on patched Windows 11 25H2, and two outlets reported the same claimed capability along with the absence of a vendor fix or CVE at the time they looked.

We are carrying this as provisional and want to be exact about why: nobody here ran it. The capability rests on the repository's own description plus secondhand reporting. What would settle it is a reproduction on a current Avast build showing the sandbox path still reachable from an unprivileged token.

One gap worth stating rather than writing around: our privilege surface could not reach CISA KEV or several other sources this run, so we cannot tell you whether anyone is tracking this as exploited in the wild. Absence of that line here is a blocked fetch, not a negative result.

Evidence
The public PrettyPrague repository states that the PoC works against fully patched Avast Antivirus on patched Windows 11 25H2 and spawns a SYSTEM shell.SecurityAffairs and Cyber Kendra reported the same claimed capability and that no vendor fix or CVE was public at the time they checked.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 1, 2026