CVE-2026-82964 Overview
CVE-2026-82964 is a local privilege escalation vulnerability in the Avast sandbox minifilter driver (aswSnx.sys) on Windows. The driver improperly preserves permissions when virtualizing files inside the sandbox. A low-privileged attacker executing inside the sandbox can escape file isolation and execute code as SYSTEM. The vulnerability is categorized under [CWE-281] Improper Preservation of Permissions.
Critical Impact
A sandboxed, low-privileged process can rewrite the security descriptor of a virtualized copy of the Security Account Manager (SAM) database, extract local NTLM password hashes, and execute code as SYSTEM.
Affected Products
- Avast Antivirus (Windows) using the aswSnx.sys sandbox minifilter driver
- AVG Antivirus (Windows) sharing the same sandbox driver stack
- Norton and other Gen Digital security products referenced in the vendor advisories
Discovery Timeline
- 2026-09-16 - CVE-2026-82964 published to the National Vulnerability Database (NVD)
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-82964
Vulnerability Analysis
The Avast sandbox virtualizes filesystem operations by creating shadow copies of files that sandboxed processes attempt to modify. When aswSnx.sys creates a virtualized copy, it duplicates the original security descriptor to preserve access control semantics. The driver opens the virtualization target object with GENERIC_WRITE and FILE_WRITE_ATTRIBUTES only. It omits WRITE_DAC, which is required to modify the Discretionary Access Control List (DACL) of the target.
Every attempt to apply the original DACL therefore fails. The failure is discarded silently, leaving virtualized copies of sensitive files with overly permissive permissions. Compounding the flaw, the IRP_MJ_CREATE callback does not strip WRITE_DAC from access requests targeting sensitive directories. A sandboxed process can therefore open a virtualized object, rewrite its security descriptor, and read privileged content.
Root Cause
The root cause is an incorrect access mask used by the driver when opening virtualization targets, combined with silent error handling that suppresses the failed DACL propagation. The absence of an IRP_MJ_SET_SECURITY callback in the driver's operation registration table is a related defense-in-depth gap but is not the primary control failure.
Attack Vector
An authenticated local user runs a process inside the Avast sandbox. The attacker requests access to a virtualized copy of a sensitive file such as the SAM hive. Because the DACL was never restricted, the attacker rewrites the security descriptor, reads the SAM database contents, and extracts local NTLM password hashes. Cracking or relaying these hashes enables code execution as SYSTEM. Refer to the GitHub PoC Repository for the published proof of concept.
Detection Methods for CVE-2026-82964
Indicators of Compromise
- Sandboxed processes issuing NtSetSecurityObject or SetSecurityInfo calls against files under Avast virtualization paths.
- Access to virtualized copies of \Windows\System32\config\SAM, SYSTEM, or SECURITY hives from non-administrative processes.
- Sudden creation of SYSTEM-level processes parented to child processes of the Avast sandbox host.
Detection Strategies
- Monitor kernel and endpoint telemetry for DACL modifications on files inside Avast sandbox virtualization directories.
- Alert on credential dumping behaviors such as reads of registry hives containing password material, aligned with MITRE ATT&CK T1003.002 (OS Credential Dumping: SAM).
- Correlate sandbox process activity with subsequent SYSTEM token acquisition or lateral movement attempts.
Monitoring Recommendations
- Enable Windows Security auditing for object access on SAM, SYSTEM, and SECURITY hives and any virtualized shadow copies.
- Track loaded versions of aswSnx.sys across the fleet to confirm patched builds are deployed.
- Ingest endpoint and driver telemetry into a centralized analytics platform for behavior correlation across sandbox escapes and credential access.
How to Mitigate CVE-2026-82964
Immediate Actions Required
- Update Avast, AVG, and Norton products to the latest vendor build that ships a corrected aswSnx.sys driver.
- Inventory endpoints running the Avast sandbox and prioritize patching systems that expose the sandbox to untrusted code or users.
- Rotate local account credentials on any host suspected of running vulnerable sandbox drivers where sandboxed code executed untrusted binaries.
Patch Information
Apply vendor updates using the Avast Antivirus Update Guide, the AVG Antivirus Update Article, and the Norton Security Solutions Guide. Consult the Gen Digital Security Advisories page for the fixed driver version and additional guidance.
Workarounds
- Disable the Avast sandbox feature on affected hosts until the patched driver is deployed, if operationally acceptable.
- Restrict interactive logon and code execution privileges for low-privileged users on systems running the vulnerable driver.
- Apply application control policies that prevent execution of untrusted binaries inside the sandbox during the remediation window.
# Verify the loaded aswSnx.sys driver version on Windows
Get-Item "C:\Windows\System32\drivers\aswSnx.sys" | Select-Object VersionInfo
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
