Zero‑Day in Avast Antivirus Enables SAM Dump and SYSTEM‑Level Shell
A publicly released proof‑of‑concept repository has exposed a local privilege escalation flaw in GenDigital's Avast Antivirus that lets an attacker extract the Windows Security Account Manager (SAM) database and obtain a command shell with NT SYSTEM privileges.
The vulnerability, originally reported by the security research collective GBHackers, is classified as a zero‑day because it is unknown to the vendor and has no existing patch. Exploiting the flaw requires only local access, meaning a malicious actor who can run code on an infected machine could potentially harvest hashed password credentials from the SAM file and then operate with the highest level of system authority.
Windows stores user password hashes in the SAM database, a protected component of the operating system. Access to these hashes enables offline cracking attempts, which can compromise not only the compromised host but also any network resources where the same credentials are reused. Gaining a shell as NT SYSTEM further allows unrestricted control over the system, including the ability to disable security tools, install persistent malware, or move laterally across a network.
Avast Antivirus, now part of GenDigital, is installed on millions of personal and business computers worldwide. The discovery raises concerns because security software is expected to act as a defensive layer, yet a flaw within it can become a powerful attack vector. While the PoC code is publicly available, there is no evidence yet of active exploitation in the wild, but the mere availability increases the risk that threat actors could adopt it quickly.
GenDigital has not issued an official comment or released a security advisory at the time of this report. Standard industry practice would see the vendor develop and distribute a patch as soon as possible, and security researchers typically advise users to apply updates promptly, employ layered defenses, and limit the execution of untrusted code to mitigate the risk until a fix arrives.
The incident underscores the ongoing challenge of securing third‑party software that operates at a privileged level. As attackers continue to target supply‑chain and security‑product vulnerabilities, experts recommend that organizations monitor vendor advisories, maintain up‑to‑date backups, and consider employing application whitelisting to reduce the attack surface posed by such zero‑day exploits.
Comments (0)
Be the first to comment.
Join the discussion