CVE-2014-9632

AVG Internet Security <2013.3495-2015.5315 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-9632. PoCs published by Parvez Anwar.

AI-analyzed exploit summary This exploit leverages an arbitrary write vulnerability in AVG Internet Security 2015 (CVE-2014-9632) to overwrite the HAL dispatch table, enabling privilege escalation on Windows XP SP3. It includes shellcode to steal a SYSTEM token and restore overwritten pointers.

Description

The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x830020f8 IOCTL call.

Exploits (1)

exploitdb WORKING POC
by Parvez Anwar · clocalwindows
https://www.exploit-db.com/exploits/35993

This exploit leverages an arbitrary write vulnerability in AVG Internet Security 2015 (CVE-2014-9632) to overwrite the HAL dispatch table, enabling privilege escalation on Windows XP SP3. It includes shellcode to steal a SYSTEM token and restore overwritten pointers.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: AVG Internet Security 2015 (2015.0.5315) with driver avgtdix.sys (15.0.0.5204)
No auth needed
Prerequisites: Windows XP SP3 32-bit · AVG Internet Security 2015 with vulnerable driver version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory x_refsource_misc
http://www.greyhathacker.net/?p=818
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35993
Vendor Advisory x_refsource_confirm
http://www.avg.com/eu-en/avg-release-notes
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/113824

Scores

EPSS 0.0181
EPSS Percentile 83.3%

Details

CWE
CWE-264
Status published
Products (2)
avg/internet_security 2013 - 2013.3495
avg/protection 2015 - 2015.5314
Published Feb 06, 2015
Tracked Since Feb 18, 2026