PT-2016-5810 · Avast · Avast Pro Antivirus+9

Kyriakos Economou

·

Published

2016-11-03

·

Updated

2016-11-04

·

CVE-2016-4025

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Avast Internet Security versions 11.x.x Avast Pro Antivirus versions 11.x.x Avast Premier versions 11.x.x Avast Free Antivirus versions 11.x.x Avast Business Security versions 11.x.x Avast Endpoint Protection versions 8.x.x Avast Endpoint Protection Plus versions 8.x.x Avast Endpoint Protection Suite versions 8.x.x Avast Endpoint Protection Suite Plus versions 8.x.x Avast File Server Security versions 8.x.x Avast Email Server Security versions 8.x.x
Description The issue allows attackers to bypass the DeepScreen feature via a DeviceIoControl call.
Recommendations For Avast Internet Security version 11.x.x, update to a version that includes a fix for this issue. For Avast Pro Antivirus version 11.x.x, update to a version that includes a fix for this issue. For Avast Premier version 11.x.x, update to a version that includes a fix for this issue. For Avast Free Antivirus version 11.x.x, update to a version that includes a fix for this issue. For Avast Business Security version 11.x.x, update to a version that includes a fix for this issue. For Avast Endpoint Protection version 8.x.x, update to a version that includes a fix for this issue. For Avast Endpoint Protection Plus version 8.x.x, update to a version that includes a fix for this issue. For Avast Endpoint Protection Suite version 8.x.x, update to a version that includes a fix for this issue. For Avast Endpoint Protection Suite Plus version 8.x.x, update to a version that includes a fix for this issue. For Avast File Server Security version 8.x.x, update to a version that includes a fix for this issue. For Avast Email Server Security version 8.x.x, update to a version that includes a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4025

Affected Products

Avast Business Security
Avast Email Server Security
Avast Endpoint Protection
Avast Endpoint Protection Plus
Avast Endpoint Protection Suite
Avast File Server Security
Avast Free Antivirus
Avast Internet Security
Avast Premier
Avast Pro Antivirus