nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-26523 CVE-2022-26523
MEDIUMRansomware
Avast Anti Rootkit kernel driver user controlled length
Record summary
CVE-2022-26523 has a selected CVSS score of 5.3 (medium). VulnCheck reports CVE-2022-26523 use in known ransomware campaigns.
Description
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 5, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
References
3avast.com
https://www.avast.com/bug-bounty sentinelone.com
https://www.sentinelone.com/labs/vulnerabilities-in-avast-and-avg-put-millions-at-risk