Security News Chaotic Eclipse Claims Avast Antivirus 0-Day Vulnerability – PoC Released

Parkinsond

Level 66
Thread author
Verified
Top Poster
Well-known
Dec 6, 2023
5,559
17,739
6,469
Researcher Chaotic Eclipse has claimed to have discovered a zero-day privilege-escalation vulnerability affecting Avast Antivirus and released a public proof-of-concept repository named PrettyPrague.

The researcher behind the project, using the GitHub handle MSNightmare, says the issue can be exploited on fully patched Avast Antivirus installations running fully updated Windows 11 25H2 systems.

The alleged flaw is described as an elevation-of-privilege vulnerability in Avast Sandbox, a component designed to isolate suspicious files and reduce the damage from potentially malicious programs.

 
That is still unverified. If it's the sandbox feature, only Avast and Norton have that and AVG don't.
Are they referring to just the standalone feature or CyberCapture? If it’s CyberCapture, then yes, AVG has it along with its sandbox feature. From my understanding of the article, they mentioned “Avast Sandbox, a component designed to isolate suspicious files and reduce the damage from potentially malicious programs.” However, this hasn’t been verified, but if true, hopefully it was reported since GEN is usually very quick at fixing issues. I believe they’re talking about the sandbox CyberCapture feature.

However, I want to Re-emphasize that if it’s CyberCapture, then yes, AVG is definitely affected, although I’m sure they will fix it very quickly.
 
Last edited:
Are they referring to just the standalone feature or CyberCapture? If it’s CyberCapture, then yes, AVG has it along with its sandbox feature. From my understanding of the article, they mentioned “Avast Sandbox, a component designed to isolate suspicious files and reduce the damage from potentially malicious programs.” However, this hasn’t been verified, but if true, hopefully it was reported since GEN is usually very quick at fixing issues. I believe they’re talking about the sandbox CyberCapture feature.
From my understanding, it's referring to the Sandbox Component where users run unknown Apps and are given limited/least privilege.
By running the POC, that will result in Privilege Escalation escaping the Sandbox then accessing the SAM file of the host.
 
I understand this is an event in it's early stages, and the best and the brightest here are probably not to concerned yet.

But allow me to issue my pet peeve. Any company who creates their product, no matter what it is, cherishes it, simply because it is tied to their name or to their personhood.

Take for example immigrants who came here in the 1900's or even after WW2.

Those who had the desire, and inclination, developed some of the best products, it could be anything; Toasters by GE, products made for Sears, furniture that lasted forever. Things made from metal, soon made with plastic, or made in China, classified as junkware consumer products.

Now we have a similar scenario with software, all owned by huge conglomerates, no longer a product made from, a desire to make something great.

And now they become, a target just like the behemoth Microsoft.
 
I think this nightmare fella must be using some Chinese AI to find the vulnerabilities. Those AI's are not tethered, I think. He's producing them too quickly.
💯💯💯 even I use Chinese AI because of it's non woke crap. Less bullshit guardrails with the advantage that they basically use and steal frontier models.
 
All praise and respect to Kaspersky!
Always my top choice.
The vuln was tested by me against K multiple times within hours of when it was first released but it didn't produce the desired action. Clearly the author also knew that it would work after multiple tries but I couldn't recreate it in a VM. Anyways I reported it to @harlan4096 who forwarded it to K and they did the needful...