SECURITY·중요도 8·2026. 09. 26.·GeekNews

Avast Antivirus 샌드박스에 진입하고 탈출하기, 2부

── KO ──────────────────

Avast의 샌드박스를 공격하는 방법을 시연한 기사입니다.

이 기사에서는 Avast 커널 드라이버의 CVE-2025-13032 취약점을 이용하여 최신 Windows 11에서 로컬 권한을 SYSTEM으로 상승시키는 전체 공격 과정을 시연합니다. 또한 사용자 입력의 길이를 여러 번 읽어 발생하는 더블 페치 결함으로 인해 페이징 풀 오버플로를 일으키는 기법도 설명됩니다. 이를 통해 보안 취약점에 대한 이해를 높일 수 있습니다.


── EN ──────────────────

The article demonstrates how to exploit Avast's sandbox vulnerabilities.

This article demonstrates the full attack process using the CVE-2025-13032 vulnerability in the Avast kernel driver to elevate local privileges to SYSTEM on the latest Windows 11. It also discusses the double-fetch flaw that causes paging pool overflow by reading the length of user input multiple times. Readers can enhance their understanding of security vulnerabilities through these demonstrations.

원문 보기 →목록으로