Researcher Chaotic Eclipse, using the GitHub handle MSNightmare, released PrettyPrague, a public proof of concept claiming a local privilege-escalation zero-day in GenDigital Avast Antivirus. The PoC allegedly abuses the Avast Sandbox component on fully patched Avast installations running fully updated Windows 11 25H2 to dump the Windows Security Account Manager (SAM) database and start a shell as NT AUTHORITY\SYSTEM.
No CVE, vendor advisory, root-cause analysis, coordinated-disclosure details, or confirmed patch was available, leaving the claim unverified. The researcher speculated that AVG and Norton products could also be affected but provided no supporting evidence; organizations using Avast should monitor vendor guidance and investigate anomalous Avast Sandbox activity, SAM access, and unexpected SYSTEM-level process creation.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
The public PrettyPrague repository attributed to MSNightmare/Chaotic Eclipse was last updated and claimed an unpatched Avast Antivirus Sandbox privilege-escalation flaw. The PoC purportedly dumps the Windows SAM database and opens an NT AUTHORITY\SYSTEM shell on fully patched Avast Antivirus and Windows 11 25H2 systems; no CVE, vendor confirmation, or patch information was provided.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.