CVE-2022-26523
Awaiting Analysis
Awaiting Analysis - Queue
Double Fetch Vulnerability in Avast and AVG Anti Rootkit Driver
Publication date: 2026-05-08
Last updated on: 2026-05-08
Assigner: MITRE
Description
Description
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| avast | avg_windows_anti_rootkit_driver | to 22.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |