Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32p2-rghv-w56x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.

In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.

EPSS

Процентиль: 30%
0.00112
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 4.4
nvd
больше 6 лет назад

In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.

EPSS

Процентиль: 30%
0.00112
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-59