CHAOTIC Eclipse, a security researcher, has released a proof-of-concept (PoC) exploit named PrettyPrague, which targets a zero-day vulnerability in GenDigital Avast Antivirus. This vulnerability allows for privilege escalation, enabling the exploit to dump the Windows SAM database and gain SYSTEM-level access, even on fully patched versions of Avast and Windows 11. The researcher suspects this flaw may also impact other GenDigital products, including AVG and Norton.
Chaotic Eclipse has a history of releasing exploits for various security products, often following criticism of how vendors handle vulnerability reporting. His previous exploits include a zero-day for Kaspersky Endpoint Security.