PT-2019-12204 · Avast · Avast Antivirus

Publicado

2019-07-18

·

Atualizado

2019-07-24

·

CVE-2019-11230

CVSS v3.1

4.4

Média

VetorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Avast Antivirus versions prior to 19.4
Description A local administrator can exploit a defect in the product by replacing the LogsUpdate.log file with a symlink, allowing them to rename arbitrary files. This can be used to rename critical product files, such as AvastSvc.exe, which can cause the product to fail to start on the next system restart.
Recommendations For versions prior to 19.4, update to version 19.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the LogsUpdate.log file to prevent symlink replacement until a patch is applied.

Exploit

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11230

Produtos afetados

Avast Antivirus