PT-2017-18274 · Avast · Avast Antivirus

Published

2017-04-27

·

Updated

2019-10-03

·

CVE-2017-8307

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avast Antivirus versions prior to 17
Description The issue allows unprivileged users to launch predefined binaries, replace or delete arbitrary files when Avast Self-Defense is disabled. It can also be exploited in conjunction with other vulnerabilities when Avast Self-Defense is enabled, allowing for Denial of Service attacks and hiding traces of a possible attack.
Recommendations For Avast Antivirus versions prior to 17, update to version 17 or later to resolve the issue. As a temporary workaround, consider enabling Avast Self-Defense to minimize the risk of exploitation. Restrict access to the LPC interface API exposed by the AvastSVC.exe Windows service to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-8307

Affected Products

Avast Antivirus