PT-2023-5683 · Avast · Avast Premium Security

Abdelhamid Naceri

·

Published

2023-02-22

·

Updated

2025-08-13

·

CVE-2023-42124

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avast Premium Security (affected versions not specified)
Description This issue allows local attackers to escalate privileges on affected installations. The flaw exists within the implementation of the sandbox feature due to incorrect authorization, enabling an attacker to execute arbitrary code outside the sandbox at medium integrity. An attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2023-06351
CVE-2023-42124
ZDI-23-1474

Affected Products

Avast Premium Security