CVE-2022-26522: High severity Avast Windows Anti Rootkit driver (aswArPot.sys) vulnerability
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26522?
CVE-2022-26522 is classified as a high severity vulnerability due to its potential for arbitrary code execution in kernel mode.
How do I fix CVE-2022-26522?
To mitigate CVE-2022-26522, users should update their Avast or AVG Windows Anti Rootkit driver to version 22.1 or later.
Who is affected by CVE-2022-26522?
CVE-2022-26522 affects users running Avast or AVG Windows Anti Rootkit drivers prior to version 22.1.
What types of attacks are possible with CVE-2022-26522?
CVE-2022-26522 can allow local attackers to execute arbitrary code or cause a denial of service through memory corruption.
When was CVE-2022-26522 disclosed?
CVE-2022-26522 was disclosed in early 2022, impacting specific versions of the Avast and AVG products.