In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of the Avast product. This bypasses the Self-Defense feature of the product, opening a door to subsequent attack on many of its components.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/bid/98084 | Third Party Advisory VDB Entry | 
| https://www.trustwave.com/Resources/Security-Advisories/Advisories/Multiple-Vulnerabilities-in-Avast-Antivirus/?fid=9201 | Exploit Technical Description Third Party Advisory | 
| http://www.securityfocus.com/bid/98084 | Third Party Advisory VDB Entry | 
| https://www.trustwave.com/Resources/Security-Advisories/Advisories/Multiple-Vulnerabilities-in-Avast-Antivirus/?fid=9201 | Exploit Technical Description Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 03:33
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.securityfocus.com/bid/98084 - Third Party Advisory, VDB Entry | |
| References | () https://www.trustwave.com/Resources/Security-Advisories/Advisories/Multiple-Vulnerabilities-in-Avast-Antivirus/?fid=9201 - Exploit, Technical Description, Third Party Advisory | 
Information
                Published : 2017-04-27 20:59
Updated : 2025-04-20 01:37
NVD link : CVE-2017-8308
Mitre link : CVE-2017-8308
CVE.ORG link : CVE-2017-8308
JSON object : View
Products Affected
                avast
- antivirus
CWE
                
                    
                        
                        CWE-269
                        
            Improper Privilege Management
