A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital's Avast Antivirus, allowing attackers with local execution access to extract the Windows Security Account Manager (SAM) database and execute a shell with NT AUTHORITYSYSTEM privileges. The flaw is located in the Avast Sandbox component and could enable a complete local takeover of the system. The PoC is compatible with any version of Avast Antivirus and has been tested on fully patched versions of Avast and Windows 11 25H2. The repository does not provide a formal release, CVE identifier, or patch details. The vulnerability may also affect other GenDigital products like AVG and Norton. Security teams are advised to monitor for suspicious activities related to Avast services and restrict local administrator access. Organizations should inventory their deployed versions and apply vendor-provided updates as they become available.