SentinelLabs disclosed two high-severity local privilege escalation vulnerabilities in the Avast and AVG Anti Rootkit driver, tracked as CVE-2022-26522 and CVE-2022-26523. The flaws affected Avast and AVG Windows products for years and could allow a non-administrator attacker to execute code in kernel mode, disable security tools, overwrite system components, corrupt the operating system, or fully compromise a device.
The researchers said the bugs potentially exposed millions to tens of millions of users and could be used in sandbox escapes, local privilege escalation chains, or as a second-stage component in browser attacks. SentinelLabs reported the issues to Avast in December 2021, and Avast addressed them in version 22.1, which was expected to reach most users through automatic updates; SentinelLabs said it had found no evidence of in-the-wild exploitation at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Avast silently fixed the two vulnerabilities in version 22.1 of affected Avast and AVG products, with most users expected to receive the update automatically.
SentinelLabs reported two high-severity privilege escalation vulnerabilities in Avast and AVG’s Anti Rootkit driver, later tracked as CVE-2022-26522 and CVE-2022-26523, to Avast in December 2021.
SentinelLabs disclosed CVE-2022-26522 and CVE-2022-26523, warning they could let non-administrator attackers gain kernel-mode code execution and potentially take over Windows devices. At the time of disclosure, SentinelLabs said it had found no evidence of in-the-wild exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.