RSS   Vulnerabilities for 'Premium security'   RSS

2021-03-29
 
CVE-2021-27241

CWE-59
 

 
This vulnerability allows local attackers to delete arbitrary directories on affected installations of Avast Premium Security 20.8.2429 (Build 20.8.5653.561). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the AvastSvc.exe module. By creating a directory junction, an attacker can abuse the service to delete a directory. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12082.

 
2020-01-13
 
CVE-2019-18894

CWE-78
 

 
In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to support Bank Mode functionality. A flaw in the processing of a command allows execution of arbitrary OS commands with the privileges of the currently logged in user. This allows for example attackers who compromised a browser extension to escape from the browser sandbox.

 

 >>> Vendor: Avast 32 Products
Avast antivirus
Avast antivirus home
Avast antivirus professional
Avast antivirus free
Avast! mobile security
Avast free antivirus
Avast internet security
Avast premier
Avast pro antivirus
Avast
Business security
Email server security
Endpoint protection
Endpoint protection plus
Endpoint protection suite
Endpoint protection suite plus
File server security
Free antivirus
Internet security
Premier
Pro antivirus
Antivirus
Premium security
Secure browser
Antivirus for linux
Antivirus pro
Antivirus pro plus
Antitrack
Avg antitrack
Avg antivirus
Secureline vpn
Retdec


Copyright 2021, cxsecurity.com

 

Back to Top