Researchers successfully exploited a double-fetch vulnerability in Avast's kernel driver on an up-to-date Windows 11 system, gaining arbitrary kernel read/write access and escalating privileges to SYSTEM. They achieved this by corrupting the RegBuffers array of an IORing object, leaking an _EPROCESS pointer via a Memory Descriptor List (MDL), repairing corrupted pool allocation headers, and ...