Impact
The vulnerability is an improper preservation of permissions in the Avast sandbox minifilter driver. When the sandbox virtualizes a file, it copies the original security descriptor but opens the target object with only write‑attributes permissions, omitting WRITE_DAC. The driver silently discards failures when attempting to apply the original DACL, leaving virtualized copies with overly permissive permissions. An attacker limited to the sandbox can thus rewrite the security descriptor of a virtualized object, read the virtualized copy of the SAM database, extract local NTLM hashes, and execute code as SYSTEM. This flaw corresponds to improper authorization (CWE‑862) and missing DACL handling (CWE‑281, CWE‑653).
Affected Systems
The affected products are Gen Digital’s antivirus families: Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security, AVG Free, AVG Internet Security, AVG Ultimate, Norton Antivirus Plus, Norton 360 Standard, Norton 360 Deluxe, and Norton 360 Advanced. The flaw exists in the sandbox driver (aswSnx.sys for Avast, avgSnx.sys for AVG, nllSnx.sys for Norton) on all release lines older than 26.7. Micro‑updates released on September 4 2026 replace the driver with version 26.7.1021.0 for the 26.7 line and 26.8.1020.0 for the 26.8 line. Installations on earlier release lines do not receive these micro‑updates and remain vulnerable.
Risk and Exploitability
The CVSS score is 8.8 and the EPSS score is below 1 %, indicating a severe but unlikely mass exploitation. The vulnerability is local; an attacker must already have execution within the sandbox. The flaw is not listed in the CISA KEV catalog. Because the fix is a driver replacement, a device restart is required to load the new driver; until the restart the system remains exposed. When present, the updated driver prevents the privilege‑enhancement path by correctly preserving DACLs and handling WRITE_DAC permissions.
OpenCVE Enrichment