Security News Chaotic Eclipse Claims Avast Antivirus 0-Day Vulnerability – PoC Released

Parkinsond

Level 66
Thread author
Verified
Top Poster
Well-known
Dec 6, 2023
5,544
17,695
6,469
Researcher Chaotic Eclipse has claimed to have discovered a zero-day privilege-escalation vulnerability affecting Avast Antivirus and released a public proof-of-concept repository named PrettyPrague.

The researcher behind the project, using the GitHub handle MSNightmare, says the issue can be exploited on fully patched Avast Antivirus installations running fully updated Windows 11 25H2 systems.

The alleged flaw is described as an elevation-of-privilege vulnerability in Avast Sandbox, a component designed to isolate suspicious files and reduce the damage from potentially malicious programs.

 
That is still unverified. If it's the sandbox feature, only Avast and Norton have that and AVG don't.
Are they referring to just the standalone feature or CyberCapture? If it’s CyberCapture, then yes, AVG has it along with its sandbox feature. From my understanding of the article, they mentioned “Avast Sandbox, a component designed to isolate suspicious files and reduce the damage from potentially malicious programs.” However, this hasn’t been verified, but if true, hopefully it was reported since GEN is usually very quick at fixing issues. I believe they’re talking about the sandbox CyberCapture feature.

However, I want to Re-emphasize that if it’s CyberCapture, then yes, AVG is definitely affected, although I’m sure they will fix it very quickly.
 
Last edited:
Are they referring to just the standalone feature or CyberCapture? If it’s CyberCapture, then yes, AVG has it along with its sandbox feature. From my understanding of the article, they mentioned “Avast Sandbox, a component designed to isolate suspicious files and reduce the damage from potentially malicious programs.” However, this hasn’t been verified, but if true, hopefully it was reported since GEN is usually very quick at fixing issues. I believe they’re talking about the sandbox CyberCapture feature.
From my understanding, it's referring to the Sandbox Component where users run unknown Apps and are given limited/least privilege.
By running the POC, that will result in Privilege Escalation escaping the Sandbox then accessing the SAM file of the host.
 
I understand this is an event in it's early stages, and the best and the brightest here are probably not to concerned yet.

But allow me to issue my pet peeve. Any company who creates their product, no matter what it is, cherishes it, simply because it is tied to their name or to their personhood.

Take for example immigrants who came here in the 1900's or even after WW2.

Those who had the desire, and inclination, developed some of the best products, it could be anything; Toasters by GE, products made for Sears, furniture that lasted forever. Things made from metal, soon made with plastic, or made in China, classified as junkware consumer products.

Now we have a similar scenario with software, all owned by huge conglomerates, no longer a product made from, a desire to make something great.

And now they become, a target just like the behemoth Microsoft.
 
  • Like
Reactions: Khushal
I think this nightmare fella must be using some Chinese AI to find the vulnerabilities. Those AI's are not tethered, I think. He's producing them too quickly.
💯💯💯 even I use Chinese AI because of it's non woke crap. Less bullshit guardrails with the advantage that they basically use and steal frontier models.