PT-2017-18274 · Avast · Avast Antivirus
Published
2017-04-27
·
Updated
2019-10-03
·
CVE-2017-8307
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avast Antivirus versions prior to 17
Description
The issue allows unprivileged users to launch predefined binaries, replace or delete arbitrary files when Avast Self-Defense is disabled. It can also be exploited in conjunction with other vulnerabilities when Avast Self-Defense is enabled, allowing for Denial of Service attacks and hiding traces of a possible attack.
Recommendations
For Avast Antivirus versions prior to 17, update to version 17 or later to resolve the issue. As a temporary workaround, consider enabling Avast Self-Defense to minimize the risk of exploitation. Restrict access to the LPC interface API exposed by the AvastSVC.exe Windows service to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avast Antivirus