CVE-2022-26522 Details
Description
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.
A double fetch vulnerability has been identified in the Avast and AVG Windows Anti-Rootkit driver, specifically in the socket connection handler of the kernel driver aswArPot.sys, prior to version 22.1. This vulnerability allows local attackers to execute arbitrary code in kernel mode or cause a denial-of-service by corrupting memory and crashing the operating system. The issue arises because the vulnerable function fetches a user-controlled length value twice, creating a race condition that attackers can exploit to manipulate the length variable and execute arbitrary code.
Users of Avast and AVG will receive the patch to version 22.1 automatically, but those with air-gapped or on-premise installations should apply the patch as soon as possible.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.avast.com/bug-bounty | [email protected] | |
| https://www.sentinelone.com/labs/vulnerabilities-in-avast-and-avg-put-millions-at-risk/ | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |