CVE-2025-13032: Critical severity Avast Avg Antivirus vulnerability
Published Nov 11, 2025
·Updated
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overflow.
Affected Software
3 affected components
Avast Avg Antivirus<25.3
All of the following
Avast Antivirus<25.3
Microsoft Windows
Remediation
Information
Upgrade to a version after >= 25.3
Event History
Nov 11, 2025
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13032?
CVE-2025-13032 has a high severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2025-13032?
To fix CVE-2025-13032, upgrade to a version of Avast/AVG Antivirus that is higher than 25.3.
3
Who is affected by CVE-2025-13032?
CVE-2025-13032 affects users of Avast/AVG Antivirus versions up to 25.3 on Windows.
4
What type of vulnerability is CVE-2025-13032?
CVE-2025-13032 is classified as a double fetch vulnerability that allows local privilege escalation.
5
Can CVE-2025-13032 be exploited remotely?
No, CVE-2025-13032 is a local vulnerability that requires physical or local access to exploit.