Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c65v-cwf9-f69v

Опубликовано: 08 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 0

Описание

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.

EPSS

Процентиль: 27%
0.00098
Низкий

0 Low

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 8.2
nvd
около 2 лет назад

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.

EPSS

Процентиль: 27%
0.00098
Низкий

0 Low

CVSS3

Дефекты

CWE-367