CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

safateam.com

104 points by safateam 13 hours ago


fathermarz - 7 hours ago

I have lost faith in signature AV and CVE feeds for that matter. Attackers test against scanners until they come back clean and avoid known fingerprints. The only way I see to catch things now is behaviour diffing through static analysis.

Disclosure: I build Vigilance, which does this.

x-complexity - 12 hours ago

Chalk another one up for "Antiviruses causing more problems than solving them".

They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.

Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.

wzdd - 11 hours ago

That's an impressively tight TOCTOU exploit!

kettlecrisp99 - 11 hours ago

[dead]