PT-2022-3452 · Avast · Avast Premium Security

Netero1010

·

Published

2022-05-19

·

Updated

2023-08-08

·

CVE-2022-28965

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Avast Premium Security versions prior to 21.11.2500
Description The issue is related to DLL hijacking vulnerabilities via the components instup.exe and wsc proxy.exe, which can allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted DLL file. This is due to the use of an unreliable path search.
Recommendations For versions prior to 21.11.2500, update to version 21.11.2500 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable components instup.exe and wsc proxy.exe to minimize the risk of exploitation.

Exploit

Fix

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2022-04230
CVE-2022-28965

Affected Products

Avast Premium Security