
Part 2 of our CVE-2025-13032 research is live. From a paged pool overflow to full LPE on Windows 11: IORing RegBuffers corruption, MDL-based kernel address leak, and SYSTEM token theft. CVE is patched. Full write-up: https://www.safateam.com/intelligence-hub/research/technical-articles/cve-2025-13032-entering-and-breaking-the-avast-antivirus-sandbox-part-2
