A PoC Turned Avast’s Malware Sandbox Into a Route to SYSTEM
A security sandbox is supposed to stop untrusted code from reaching the rest of a computer. The Avast PrettyPrague privilege escalation disclosure claims to reverse that relationship, using Avast’s own sandbox as a route to the most powerful local security context in Windows.
According to its author, PrettyPrague can abuse a vulnerability in Avast Sandbox to dump the Windows Security Account Manager database and spawn a command shell as NT AUTHORITY\SYSTEM. The repository says the technique worked with fully updated Avast Antivirus on a patched Windows 11 25H2 system.
Gen Digital has confirmed that a security vulnerability affected a subset of its products, including Avast Antivirus, and could allow an attacker to elevate privileges. In a statement provided to SecurityWeek, the company said it had fixed the issue and urged customers to keep their products up to date.
Those facts justify prompt action, but not a claim of universal exposure. Gen Digital has not publicly identified the complete affected-product list or fixed-version matrix in the sources reviewed by BlackTree. No CVE, CVSS score or confirmed malicious exploitation has been published. BlackTree has not independently reproduced the proof of concept.
The protective boundary became the route upwards
Sandboxing is meant to place suspicious activity inside a restricted environment. The contained process should receive less authority, fewer resources and a narrower view of the host than ordinary software. PrettyPrague alleges that the privileged machinery enforcing that separation can instead be steered across the boundary it is meant to protect.
SYSTEM access matters because it is not simply another administrative label. A process running as NT AUTHORITY\SYSTEM can interact with protected operating-system resources, services and data that a standard user cannot normally reach. In a real intrusion, that authority could support credential access, security-control tampering, persistence and access to data belonging to other users or services.
The claimed SAM access adds another sensitive element. Windows stores local account information and password-derived credential material in the Security Account Manager database. Access to that database does not automatically reveal every password or compromise every network identity, but it can give an attacker valuable material for offline analysis and follow-on activity.
This is still a local privilege-escalation disclosure. PrettyPrague is not described as a remote initial-access exploit. An attacker would first need an authorised or unauthorised way to run code in a lower-privileged local context. Phishing, stolen sessions, malicious downloads and another vulnerability can provide that foothold, but they are separate steps.
What the Avast PrettyPrague privilege escalation PoC contains
The PrettyPrague repository was first published on 30 August 2026 at 16:43 UTC. Its README identifies the target as Avast Antivirus and describes the issue as an elevation-of-privilege vulnerability in Avast Sandbox. The repository includes source code and a compiled release, which materially shortens the path for researchers and attackers who want to study the claimed technique.
The author states that the proof of concept dumps the SAM database and opens a full SYSTEM shell. The author also claims compatibility with any Avast Antivirus version and reports testing against a fully patched Avast installation and Windows 11 25H2.
Those are the researcher’s claims, not an affected-version statement from Gen Digital. A successful demonstration on one updated test system does not establish that every Avast edition, build, configuration or supported Windows release is affected. The repository does not provide the kind of complete product matrix that administrators need for inventory-based remediation.
The author speculates that AVG and Norton may share the issue. BlackTree has found no public evidence in the reviewed sources that establishes either product as affected. Gen Digital confirmed only that the vulnerability involved a subset of Gen products, including Avast Antivirus, without naming the rest of that subset.
Gen Digital says the flaw is fixed
SecurityWeek published Gen Digital’s response on 7 September. The company said it had recently learned of a vulnerability affecting a subset of Gen products, including Avast Antivirus, that could permit privilege elevation. It said its security-response process was activated immediately, the issue was fixed and customers should keep their products updated.
That statement is the strongest vendor confirmation currently available in the public sources reviewed for this article. It confirms a real privilege-escalation issue and a delivered fix. It does not confirm every impact described in the repository, identify every affected product or state which product build contains the correction.
Gen Digital’s public security-advisory index did not show a clearly identifiable PrettyPrague entry, CVE or fixed-version matrix when BlackTree checked it on 8 September 2026. The absence of a visible bulletin should not be read as evidence that the update was not delivered. It does mean that defenders have less public information than they normally receive from a conventional vulnerability advisory.
A fix without a version matrix leaves an assurance gap
Automatic updating is valuable, but it is not the same as verifiable remediation. Security teams need to know which products and versions were affected, which release first contained the fix and how an administrator can confirm that a specific endpoint received it.
Without that information, an organisation may see an endpoint report that Avast is current while still being unable to map the installed build to the corrected code. Managed environments also need to account for machines that were offline, paused, isolated, frozen in a virtual desktop image or unable to reach the normal update service.
The disclosure therefore has two clocks. The first is the product-update clock, which Gen Digital says has already moved to a fixed state. The second is the assurance clock, which remains incomplete until customers can verify the affected and corrected versions across their estates.
Public code changes the urgency, not the exploitation status
A public proof of concept gives other researchers a concrete artefact to inspect, test and modify. It can remove much of the discovery work needed to understand a vulnerability and can expose the assumptions on which a privileged component relies.
That does not prove criminal exploitation. BlackTree found no confirmed malicious campaign using PrettyPrague and no report of scanning, breaches or victims tied to it. Organisations should separate three states clearly: public exploit code exists, a vendor has confirmed and fixed a privilege-escalation vulnerability, and exploitation in the wild has not been established.
The wider pattern is nevertheless important. BlackTree recently examined how CrowdStrike’s own clean-up feature could become a path to SYSTEM. The products, technical mechanisms and vendor responses are different, but both disclosures show why high-privilege security workflows must treat user-controlled input as hostile at every stage.
What Avast customers should do now
- Allow Avast and other Gen security products to update through their normal trusted update mechanism. Do not download unofficial fixes or repackaged installers.
- Confirm that managed endpoints are running current product components, not merely that an update policy is enabled.
- Investigate endpoints that have been offline, isolated or unable to contact the vendor update service since the fix was delivered.
- Monitor Gen Digital’s security-advisory page and support channels for a formal identifier, affected-product list and fixed-version matrix.
- Review telemetry for unexpected SYSTEM-level command shells, unusual access to the SAM registry hive and privilege changes initiated through endpoint-security processes.
- Treat evidence of suspicious SAM access or a SYSTEM shell as an incident-response lead. Isolate the host, preserve evidence and rotate credentials according to the scope of the investigation.
- Do not run the public proof of concept on production systems. Any authorised validation belongs in an isolated lab with an explicit testing plan.
Defenders should avoid replacing uncertainty with theatre. Removing Avast without a migration plan can reduce protection and create a different operational risk. The proportionate response is to update, verify, monitor and press for enough version information to prove remediation.
The more authority a security tool holds, the more carefully it must be distrusted
Antivirus and endpoint-security products need deep access to inspect files, observe processes and intervene before malicious code can act. That authority is part of their value. It is also why a defect inside one of their privileged workflows can have consequences beyond those of an ordinary desktop application.
The Avast PrettyPrague privilege escalation story is arresting because it alleges that the containment boundary itself became the escalation mechanism. Gen Digital’s response says the underlying privilege-escalation issue is fixed. Customers now need the public details that turn that assurance into something they can measure across real endpoints.
Questions about PrettyPrague
Does PrettyPrague remotely compromise an Avast computer?
No remote initial-access path has been established in the reviewed sources. PrettyPrague is described as a local privilege-escalation proof of concept, which means an attacker first needs a way to run code on the endpoint.
Has Gen Digital fixed the vulnerability?
Gen Digital told SecurityWeek that it had fixed the issue and advised customers to keep their products updated. The public sources reviewed by BlackTree did not include a fixed build number or complete affected-product matrix.
Are AVG and Norton affected?
That has not been publicly established. The PrettyPrague author speculated that other Gen Digital products might be affected, but Gen Digital’s reported statement named Avast Antivirus and did not publish the rest of the affected subset.
Is PrettyPrague being used by attackers?
No confirmed malicious exploitation has been reported in the sources reviewed for this article. Public proof-of-concept availability increases exposure, but it is not proof of an active campaign.
Sources and further reading
- Nightmare Eclipse: PrettyPrague repository, first published 30 August 2026 at 16:43 UTC.
- SecurityWeek: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits, published 7 September 2026 at 08:15 ET and updated at 12:28 ET. This is the source for Gen Digital’s statement.
- Gen Digital security advisories, checked 8 September 2026.
This article provides general security information. It is not incident-response, legal or product-selection advice.


