← Back to driver explorer
Driver intelligenceVulnerableVerified
aswArPot.sys
Avast and AVG Anti Rootkit driver aswArPot.sys versions before 22.1 are affected by CVE-2022-26522 and CVE-2022-26523. Double-fetch races in kernel handlers allow a non-administrator user to corrupt kernel memory and execute code in kernel context, enabling local privilege escalation and security-product bypass.
Known samples 3
0 recorded TRUE · 1 recorded FALSE · 2 unknown for loading despite HVCI. Results apply to individual samples.
aswArPot.sysSample 1 · HVCI unknown
- MD5
13e5678932fe26a7a7f864acbff40e82- SHA1
090e5427ec21ee0d69f52ed2eb99bb5f806ce7d7- SHA256
bf5beb8560b85454ded94d2954c446970ab44dc2eeb83d80170ea3a68afa1787- Imphash
26150d69f50aa9247c3f3f17521d18a2- Authentihash MD5
be022cce821bd43c2a36b467bdc67b5c- Authentihash SHA1
3f5e1bc857083fd43bea9564d0ebe9970ca96384- Authentihash SHA256
b2da4e88826d1a4ea2532278c5bf2b9ad50ed3acd09d283c2a48fc661a72483e- Machine
- AMD64
- Version
- 20.1.44.0
- Publisher
- AVG Technologies CZ, s.r.o.
aswArPot.sysSample 2 · HVCI unknown
- MD5
54d015e3c3f31090db762f0dd5ad43c0- SHA1
be27b16ae4225403c97142e4f91b4b7e95694d60- SHA256
421cb64792a32ce79db7c8c07db4fb58bf105e58a7acf3cf1e6b5135e37795cf- Imphash
e951e0b26d5c36b13f3da573ac4c7b54- Authentihash MD5
c2fb41555ed290bf5fdf40ca7659fc91- Authentihash SHA1
1e21ec423f6127799b1e505e75deb7e99395f94d- Authentihash SHA256
5234c53ef95231a1848eb4947f8f7390463d9e759af706f19cc3ce2b0f9eae61- Machine
- AMD64
- Version
- 21.4.237.0
- Publisher
- AVG Technologies CZ, s.r.o.
aswArPot.sysSample 3 · HVCI FALSE
- MD5
a179c4093d05a3e1ee73f6ff07f994aa- SHA1
5d6b9e80e12bfc595d4d26f6afb099b3cb471dd4- SHA256
4b5229b3250c8c08b98cb710d6c056144271de099a57ae09f5d2097fc41bd4f1- Imphash
3702511999371bac8982d01820dd70f2- Authentihash MD5
66d55dcf5fe5e1b60f32880d48207105- Authentihash SHA1
b8b5e5951f1c4148537e9850f2b577a453e4c045- Authentihash SHA256
c0c131bc8d6c8b5a2be32474474b1221bce1289c174c87e743ed4a512f5571d4- Machine
- AMD64
- Version
- 21.1.187.0
- Publisher
- AVAST Software
Recorded command
sc.exe create aswArPot.sys binPath=C:\windows\temp\aswArPot.sys type=kernel && sc.exe start aswArPot.sysElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
- https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules
- https://github.com/magicsword-io/LOLDrivers/issues/409
- https://github.com/fluffycats31/vulnerable-drivers
- https://www.sentinelone.com/labs/vulnerabilities-in-avast-and-avg-put-millions-at-risk/
- https://nvd.nist.gov/vuln/detail/CVE-2022-26522
- https://nvd.nist.gov/vuln/detail/CVE-2022-26523
Acknowledgement: @mattnotmax

