Chaotic Eclipse Claims Avast Antivirus 0-Day Vulnerability – PoC Released
Brief
Researcher Chaotic Eclipse has claimed to have discovered a zero-day privilege-escalation vulnerability affecting Avast Antivirus and released a public proof-of-concept repository named PrettyPrague.
The researcher behind the project, using the GitHub handle MSNightmare, says the issue can be exploited on fully patched Avast Antivirus installations running fully updated Windows 11 25H2 systems.
The alleged flaw is described as an elevation-of-privilege vulnerability in Avast Sandbox, a component designed to isolate suspicious files and reduce the damage from potentially malicious programs.
According to the GitHub advisory from Chaotic Eclipse , the proof of concept abuses the sandbox mechanism to access the Windows Security Account Manager, or SAM, database and open a command shell with NT AUTHORITY\SYSTEM privileges.
SYSTEM is the most powerful local security context on Windows.
