PT-2019-12281 · Avira · Avira Free Security Suite

Silton Santos

·

Published

2019-08-29

·

Updated

2020-08-24

·

CVE-2019-11396

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avira Free Security Suite version 10
Description An issue in Avira Free Security Suite allows unprivileged users to obtain SYSTEM privileges due to permissive access rights on the SoftwareUpdater folder. This can be exploited by creating pseudo-symbolic links to arbitrary files, which can be used to achieve arbitrary file creation when an update occurs. The privileged service sets access rights, offering write access to the Everyone group in any directory.
Recommendations For Avira Free Security Suite version 10, consider restricting access to the SoftwareUpdater folder and its configuration files to prevent unprivileged users from replacing files with pseudo-symbolic links until a fix is available. As a temporary workaround, restrict write access to the Everyone group in any directory to minimize the risk of exploitation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11396

Affected Products

Avira Free Security Suite