PT-2021-24230 · Avast · Avast Antivirus

Published

2021-12-27

·

Updated

2023-02-11

·

CVE-2021-45337

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Avast Antivirus versions prior to 20.8
Description: A privilege escalation issue exists in the Self-Defense driver of Avast Antivirus, allowing a local user with SYSTEM privileges to gain elevated privileges. This is achieved by "hollowing" the process wsc proxy.exe, potentially leading to the acquisition of antimalware protection.
Recommendations: For Avast Antivirus versions prior to 20.8, update to version 20.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the wsc proxy.exe process to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2021-45337

Affected Products

Avast Antivirus