SAFA details the full exploitation of CVE-2025-13032, turning a double-fetch vulnerability in Avast's kernel driver into a local privilege escalation to SYSTEM on Windows 11.
32 comments
Disclosure: I build Vigilance, which does this.
They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.
Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.
IMO it would make more sense to run every app in its own scaled down VM, like Microdroid for Android. Windows 10 had Microsoft Defender Application Guard for Microsoft Edge, and as far as security goes it was a fortress.
Too bad they discontinued it, and that performance was subpar. I would have loved to see them develop the idea more.
How would you deal with a password manager or a clipboard in these cases, for example, without increasing friction for users ?
Performance doesn't have to be supbar, infact with the right properties and focus on being lightweight - I see 90% of native performance.
I work on this as context: https://github.com/smol-machines/smolvm
Either you end up with something don't work, too lax, or just DoS the user with permission dialog.
You want to keep a building secure, so you have some structure of access and key managment, who has access to what and who do you let in.
Then you let access and key managment slide, your front-desktop lets in some shady people and their is a hole in your back wall.
The solution: add scaffolding around the facade and empower some security service staff to enter every room through every window and chime in on every front desk decision.
I'm not sure it's doable with current OS architectures, though.
Read the full thread on Hacker News →
Related stories
- Hacker News · 1 points · 7 days ago
- TCP SACK PANIC - Kernel vulnerabilities - CVE-2019-11477, CVE-2019-11478 & CVE-2019-11479access.redhat.comLobsters · 1 points · over 7 years ago
- Hacker News · 1 points · 4 days ago
- Citrix NetScaler Remote Code Executionsupport.citrix.comHacker News · 2 points · 3 days ago
- Sandbox-first AI coding harnesschock.wsHacker News · 1 points · 4 days ago
- Hacker News · 1 points · 2 days ago