CVE-2022-26522
7.8Avast and AVG · Windows Anti Rootkit driver
A double fetch vulnerability in the Avast and AVG Windows Anti Rootkit driver allows local attackers to achieve arbitrary code execution in kernel mode or cause a denial of service.
Executive summary
A double fetch vulnerability in the Avast and AVG Windows Anti Rootkit driver before version 22.1 allows local authenticated attackers to achieve arbitrary code execution in kernel mode or trigger a denial of service.
Vulnerability
This flaw is a double fetch memory corruption vulnerability located in the socket connection handler of the aswArPot.sys driver, allowing local low-privileged attackers to execute arbitrary code or crash the operating system.
Business impact
A successful exploit grants local attackers complete control over the compromised system at the kernel level, potentially leading to total system compromise, data theft, and persistent malware installation. The CVSS score of 7.8 indicates a high severity threat that requires prompt attention to protect endpoints against local privilege escalation vectors.
Remediation
Immediate Action: Update the Avast or AVG Windows Anti Rootkit driver to version 22.1 or later via the vendor security advisory.
Proactive Monitoring: Monitor endpoint systems for unexpected driver crashes, blue screen of death events, or unauthorized local process executions.
Compensating Controls: Ensure host-based endpoint detection and response (EDR) solutions are active to identify and block unauthorized kernel-level activities and privilege escalation attempts.
Exploitation status
Public Exploit Available: No - As of May 9, 2026, there is no confirmed public exploit in the available data.
Analyst recommendation
Organizations utilizing affected Avast and AVG products must prioritize updating the Anti Rootkit driver to version 22.1 or higher immediately. Because this vulnerability permits kernel-level code execution, swift application of the vendor patch is critical to prevent total host compromise from local threat actors.