Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privileges by calling unnecessarily powerful internal methods of the main antivirus service which could lead to the (1) arbitrary file delete, (2) write and (3) reset security.
References
Link | Resource |
---|---|
https://github.com/the-deniss/Vulnerability-Disclosures/tree/main/CVE-2021-AVST1.1 | Exploit Third Party Advisory |
https://github.com/the-deniss/Vulnerability-Disclosures/tree/main/CVE-2021-AVST1.2 | Exploit Third Party Advisory |
https://github.com/the-deniss/Vulnerability-Disclosures/tree/main/CVE-2021-AVST1.3 | Exploit Third Party Advisory |
https://www.avast.com/hacker-hall-of-fame/en/researcher-david-eade-reports-antitrack-bug-to-avast-0 | Vendor Advisory |
Configurations
History
12 Jul 2022, 17:42
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
07 Jan 2022, 20:42
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:avast:antivirus:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 7.2
v3 : 7.8 |
References | (MISC) https://www.avast.com/hacker-hall-of-fame/en/researcher-david-eade-reports-antitrack-bug-to-avast-0 - Vendor Advisory | |
References | (MISC) https://github.com/the-deniss/Vulnerability-Disclosures/tree/main/CVE-2021-AVST1.2 - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/the-deniss/Vulnerability-Disclosures/tree/main/CVE-2021-AVST1.1 - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/the-deniss/Vulnerability-Disclosures/tree/main/CVE-2021-AVST1.3 - Exploit, Third Party Advisory | |
CWE | CWE-269 |
27 Dec 2021, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-12-27 14:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-45338
Mitre link : CVE-2021-45338
CVE.ORG link : CVE-2021-45338
JSON object : View
Products Affected
avast
- antivirus
CWE