Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Invisible Unicode Characters Evade Phishing Detection in Millions of Emails
September 4, 2026
Hackers Exploit AI Models Claude, Qwen, DeepSeek for Cyberattacks
September 4, 2026
Microsoft Exchange Online Outage Delays External Emails
September 4, 2026
Home/CyberSecurity News/Critical Avast Antivirus 0-Day Vulnerability CVE-2023-32315 Exploited, PoC Released
CyberSecurity News

Critical Avast Antivirus 0-Day Vulnerability CVE-2023-32315 Exploited, PoC Released

Key Takeaways A security researcher has publicly released a proof-of-concept (PoC) for a zero-day local privilege escalation vulnerability affecting Avast Antivirus. The alleged flaw, dubbed...

Sarah simpson
Sarah simpson
September 3, 2026 3 Min Read
8 0

Key Takeaways

  • A security researcher has publicly released a proof-of-concept (PoC) for a zero-day local privilege escalation vulnerability affecting Avast Antivirus.
  • The alleged flaw, dubbed “PrettyPrague,” targets the Avast Sandbox component, allowing an attacker to gain NT AUTHORITYSYSTEM privileges on fully patched Windows 11 systems running Avast.
  • The PoC can dump the Windows Security Account Manager (SAM) database and open a SYSTEM-level command shell.
  • As of this report, there is no official CVE, vendor advisory, or confirmed patch from GenDigital (Avast’s parent company).

Unverified Avast Antivirus Zero-Day PoC Emerges, Raising Privilege Escalation Concerns

A cybersecurity researcher, identified as Chaotic Eclipse, claims to have uncovered and publicly demonstrated a zero-day vulnerability within Avast Antivirus. The researcher has released a proof-of-concept (PoC) under the name “PrettyPrague,” which reportedly facilitates local privilege escalation on systems utilizing the popular antivirus software.

Table Of Content

  • Key Takeaways
  • Unverified Avast Antivirus Zero-Day PoC Emerges, Raising Privilege Escalation Concerns
  • The Avast Sandbox Under Scrutiny
  • PoC Claims Broad Avast Impact, Unverified for Other GenDigital Products
  • What You Should Do

The individual behind the project, operating under the GitHub handle MSNightmare, asserts that this flaw remains exploitable even on Avast Antivirus installations that are fully updated and running on the latest Windows 11 25H2 systems. This suggests the vulnerability bypasses current defensive measures.

The Avast Sandbox Under Scrutiny

The core of the alleged vulnerability resides within the Avast Sandbox, a critical component designed to contain and analyze suspicious files in an isolated environment, thereby minimizing potential damage from malicious software. The flaw is described as an elevation-of-privilege vulnerability within this sandbox mechanism.

According to the GitHub advisory from Chaotic Eclipse, the PoC leverages an exploit against the sandbox to gain unauthorized access to the Windows Security Account Manager (SAM) database. This access then enables the attacker to initiate a command shell with NT AUTHORITYSYSTEM privileges.

NT AUTHORITYSYSTEM represents the highest level of local security context on a Windows operating system. An attacker who has already achieved initial code execution on a target machine could exploit such a local privilege escalation flaw to bypass restrictions imposed on standard user accounts. This could then allow them to access sensitive credentials, disable crucial security controls, install persistent backdoors, or modify critical operating system configurations without hindrance.

PoC Claims Broad Avast Impact, Unverified for Other GenDigital Products

The public repository for “PrettyPrague” broadly asserts compatibility with all versions of Avast Antivirus. However, this claim has not been independently corroborated by an official vendor advisory or a recognized public CVE record. The project author also speculates that other products under the GenDigital umbrella, such as AVG and Norton, might also be susceptible. Nevertheless, no concrete technical evidence has been presented to substantiate these broader product impact claims. Organizations should consider these wider assertions unverified until an official assessment is released by GenDigital.

The repository contains various project files, including C and C++ source code, Windows-specific headers, a compiled x64 release directory, and a file named offreg.lib. Its explicit goal is to exploit the purported weakness in the Avast Sandbox to dump the SAM database and launch a SYSTEM-level shell. The repository was last updated on August 30, 2026, and remains publicly accessible, increasing the likelihood that it will be examined by other researchers, defensive teams, and potentially malicious actors.

While the public release of a PoC can accelerate defensive validation efforts, it simultaneously reduces the window for affected organizations to implement protective measures before potential exploitation occurs.

What You Should Do

  • Monitor Official Advisories: Keep a close watch on official security advisories from GenDigital (Avast’s parent company) for any confirmation, CVE assignment, or patch availability.
  • Review Endpoint Telemetry: Investigate endpoint telemetry for any unusual child processes spawned by Avast-related services or sandbox components, particularly those executing privileged commands.
  • Inspect SAM Database Access: Actively look for unexpected access attempts to the Windows Security Account Manager (SAM) database or unusual registry activity involving security-sensitive hives.
  • Detect SYSTEM Process Anomalies: Identify any new processes running with SYSTEM privileges that lack a legitimate administrative explanation.
  • Enhance Detection Rules: Implement endpoint detection rules focused on suspicious execution chains, specifically where low-privileged user processes interact with antivirus sandbox services before privileged command interpreters or credential-access tools are launched.
  • Verify Product Versions: Confirm the installed version and configuration of Avast Antivirus across your environment.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

SweepLED Device Detects Hidden Cameras

Next Post

Claude AI Outage Impacts Mythos, Fable, and Opus Products

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Archer Flaws Let Attackers Run Remote Code
September 4, 2026
Plex Patches Critical Vulnerabilities in Media Server
September 4, 2026
Trezor Confirms ShipMonk Breach Exposed 67,000 US Customers
September 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us