CVE-2026-82964: Gen Digital Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened the virtualization target object with GENERIC_WRITE and FILE_WRITE_ATTRIBUTES only, omitting WRITE_DAC. Every attempt to apply the original DACL therefore failed, and the failure was discarded silently, leaving virtualized copies of sensitive files with permissive permissions. Because the IRP_MJ_CREATE callback additionally did not strip WRITE_DAC for sensitive directories, a sandboxed process could rewrite the security descriptor of a virtualized object, read the virtualized copy of the SAM database, extract local NTLM password hashes and execute code as SYSTEM. The absence of an IRP_MJ_SET_SECURITY callback in the driver's operation registration table is a related defense-in-depth gap, but it is not the control that prevents this attack.
Affected products
- Gen Digital Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security: before 26.8 (fixed in 26.8)
- Gen Digital Avg Antivirus Free, Avg Internet Security, Avg Ultimate: before 26.8 (fixed in 26.8)
- Gen Digital Norton Antivirus Plus, Norton 360 Standard, Norton 360 Deluxe, Norton 360 Advanced: before 26.8 (fixed in 26.8)
Published 2026-09-16. Last modified 2026-09-17.