SAFA details the full exploitation of CVE-2025-13032, turning a double-fetch vulnerability in Avast's kernel driver into a local privilege escalation to SYSTEM on Windows 11.

115 points•safateam•6 days ago•32 comments•

32 comments

fathermarz6 days ago
I have lost faith in signature AV and CVE feeds for that matter. Attackers test against scanners until they come back clean and avoid known fingerprints. The only way I see to catch things now is behaviour diffing through static analysis.

Disclosure: I build Vigilance, which does this.

nikanj6 days ago
The point of AV is to catch that PCI DSS stamp of approval, not catch malware. Regulatory capture is the best marketing strategy
x-complexity6 days ago
Chalk another one up for "Antiviruses causing more problems than solving them".

They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.

Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.

Batman86753096 days ago
I'm a firm believer that hardware virtualization is the way forward for security. Qubes OS has the right idea, but running an entire OS for every application is demanding.

IMO it would make more sense to run every app in its own scaled down VM, like Microdroid for Android. Windows 10 had Microsoft Defender Application Guard for Microsoft Edge, and as far as security goes it was a fortress.

Too bad they discontinued it, and that performance was subpar. I would have loved to see them develop the idea more.

stingraycharles6 days ago
Aren’t you then just moving the responsibility from OS (process isolation) to the CPU ? And doesn’t this whole thing break with practical realities, such as processes needing to interact with each other ?

How would you deal with a password manager or a clipboard in these cases, for example, without increasing friction for users ?

mitxela6 days ago
Processes are already hardware paravirtualization, and some early implementations even called them VMs. However, https://xkcd.com/2044/ is inescapable.
binsquare5 days ago
I work on making this a reality with an embeddable VM.

Performance doesn't have to be supbar, infact with the right properties and focus on being lightweight - I see 90% of native performance.

I work on this as context: https://github.com/smol-machines/smolvm

j16sdiz6 days ago
Sandbox or virtualize everything does not eliminate the need to share data. Something control that permission, and it is the weakest link.

Either you end up with something don't work, too lax, or just DoS the user with permission dialog.

atoav6 days ago
No what they are is:

You want to keep a building secure, so you have some structure of access and key managment, who has access to what and who do you let in.

Then you let access and key managment slide, your front-desktop lets in some shady people and their is a hole in your back wall.

The solution: add scaffolding around the facade and empower some security service staff to enter every room through every window and chime in on every front desk decision.

oblio6 days ago
I would say white listing will have to happen for everything in the near future: applications, ports, URLs (including fragments!), filesystem hierarchies, basically everything.

I'm not sure it's doable with current OS architectures, though.

ulimn6 days ago
Isn't the model of AppArmor or SELinux a good approach to tackle this problem?
codedokode6 days ago
Antivirus is not a bad thing. Imagine running a company where there are 100 employees that click every link and open every attachment. Definitely safer with an antivirus.
master-lincoln6 days ago
I imagined it with employees on Linux and it wasn't clear to me it's definitely safer with an antivirus software. You are just stating things without explaining yourself...
wzdd6 days ago
That's an impressively tight TOCTOU exploit!

Read the full thread on Hacker News →

Related stories