PT-2022-3452 · Avast · Avast Premium Security
Netero1010
·
Published
2022-05-19
·
Updated
2023-08-08
·
CVE-2022-28965
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Avast Premium Security versions prior to 21.11.2500
Description
The issue is related to DLL hijacking vulnerabilities via the components instup.exe and wsc proxy.exe, which can allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted DLL file. This is due to the use of an unreliable path search.
Recommendations
For versions prior to 21.11.2500, update to version 21.11.2500 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable components instup.exe and wsc proxy.exe to minimize the risk of exploitation.
Exploit
Fix
Untrusted Search Path
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avast Premium Security