PT-2025-20564 · Avast · Avast Cleanup Premium

Vladislav Berghici

·

Published

2025-05-09

·

Updated

2025-07-29

·

CVE-2024-13961

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avast Cleanup Premium version 24.2.16593.17810
Description The issue allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a time-of-check to time-of-use (TOCTTOU) attack. This is achieved by exploiting the TuneupSvc in Avast Cleanup Premium on Windows 10 Pro x64.
Recommendations For Avast Cleanup Premium version 24.2.16593.17810, consider disabling the TuneupSvc service as a temporary workaround until a patch is available. Restrict access to the vulnerable service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13961
ZDI-25-696

Affected Products

Avast Cleanup Premium